Lucene search

K
ibmIBMA86C0878EE35D908C7536BFADD31FA053398DAB7CC9CC30542164462DBA72CF7
HistoryApr 28, 2021 - 6:35 p.m.

Security Bulletin: Security vulnerability in IBM Jazz Team Server affects multiple IBM Rational products based on IBM Jazz technology (CVE-2014-6131, CVE-2014-6129)

2021-04-2818:35:50
www.ibm.com
16
ibm jazz team server
security vulnerability
rational collaborative lifecycle management
rational quality manager
rational team concert
rational requirements composer
rational doors next generation
rational engineering lifecycle manager
rational rhapsody design manager
rational software architect design manager
cve-2014-6129
cve-2014-6131
upgrade
remediation
ifix2
ifix4

EPSS

0.001

Percentile

43.4%

Summary

Security vulnerabilities have been identified in the IBM Jazz Team Server affecting the following IBM Jazz Team Server based applications: Collaborative Lifecycle Management (CLM), Rational Requirements Composer (RRC), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM).

Vulnerability Details

CVEID: CVE-2014-6129

Description: IBM Rational Jazz Team Server (JTS) products allow an authenticated user with in depth knowledge of JTS to delete another user’s dashboard.

**CVSS Base Score:**3.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/96809&gt; for the current score *CVSS Environmental Score:**Undefined CVSS Vector:(AV:N/AC:M/Au:S/C:N/I:N/A:P) ** **

CVEID: CVE-2014-6131

Description: IBM Rational Jazz Team Server (JTS) products allow an authenticated user with in depth knowledge of JTS to read another user’s dashboard.

**CVSS Base Score:**3.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/96811&gt; for the current score *CVSS Environmental Score:**Undefined **CVSS Vector: **(AV:N/AC:M/Au:S/C:P/I:N/A:N)

Affected Products and Versions

Rational Collaborative Lifecycle Management 3.0.1 - 5.0.2

Rational Quality Manager 2.0 - 2.0.1
Rational Quality Manager 3.0 - 3.0.1.6
Rational Quality Manager 4.0 - 4.0.7
Rational Quality Manager 5.0 - 5.0.2

Rational Team Concert 2.0 - 2.0.0.2
Rational Team Concert 3.0 - 3.0.6
Rational Team Concert 4.0 - 4.0.7
Rational Team Concert 5.0 - 5.0.2

Rational Requirements Composer 2.0 - 2.0.0.4
Rational Requirements Composer 3.0 - 3.0.1.6
Rational Requirements Composer 4.0 - 4.0.7

Rational DOORS Next Generation 4.0 - 4.0.7
Rational DOORS Next Generation 5.0 - 5.0.2

Rational Engineering Lifecycle Manager 1.0- 1.0.0.1
Rational Engineering Lifecycle Manager 4.0.3 - 4.0.7
Rational Engineering Lifecycle Manager 5.0 - 5.0.2

Rational Rhapsody Design Manager 3.0 - 3.0.1
Rational Rhapsody Design Manager 4.0 - 4.0.7
Rational Rhapsody Design Manager 5.0 - 5.0.2

Rational Software Architect Design Manager 3.0 - 3.0.1
Rational Software Architect Design Manager 4.0 - 4.0.7
Rational Software Architect Design Manager 5.0 - 5.0.2

Remediation/Fixes

For the 5.x releases, upgrade to version 5.0.2 iFix2 or later

For the 3.x releases upgrade to version 3.0.1.6 iFix 5 or later

For the 3.x releases of Rational Software Architect Design Manager and Rhapsody Design Manager, if you cannot upgrade to 4.0.7 or 5.0, contact IBM support for guidance.

For the 2.x releases, contact IBM support for additional details on the fix.

For the 1.x releases of Rational Engineering Lifecycle Manager, contact IBM support for additional details on the fix.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

43.4%

Related for A86C0878EE35D908C7536BFADD31FA053398DAB7CC9CC30542164462DBA72CF7