Lucene search

K
ibmIBMF8E21E22BBD59DA4E36EFB1691DE04923003ACD8B571119B3561711837177CCB
HistoryJun 17, 2018 - 4:59 a.m.

Security Bulletin: Rational Test Control Panel component in Rational Test Workbench and Rational Test Virtualization Server affected by Castor Library vulnerablity (CVE-2014-3004)

2018-06-1704:59:34
www.ibm.com
12

EPSS

0.016

Percentile

87.6%

Summary

The Castor Project Castor library is vulnerable affecting the Rational Test Control Panel component in IBM Rational Test Workbench and Rational Test Virtualization Server.

Vulnerability Details

CVE ID: CVE-2014-3004

Description: Castor Library could allow a remote attacker to obtain sensitive information, caused by an XML External Entity Injection (XXE) error when processing XML data. By sending specially-crafted XML data, an attacker could exploit this vulnerability to obtain sensitive information.

CVSS Base Score: 5.0 **CVSS Temporal Score:**See <https://exchange.xforce.ibmcloud.com/vulnerabilities/93519&gt; for the current score *CVSS Environmental Score:**Undefined CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

Affected Products and Versions

Rational Test Control Panel component in Rational Test Virtualization Server and Rational Test Workbench versions:

  • 8.0 - 8.0.0.3
  • 8.0.1 - 8.0.1.4
  • 8.5 - 8.5.0.2
  • 8.5.1 - 8.5.1.3
  • 8.6 - 8.6.0.2

Remediation/Fixes

The fixes for the CVE(s) mentioned above have been incorporated into the 1.3.3 release of Castor library, and included in a set of new fixpacks available from IBM.

Upgrade your installation as follows:

Visit IBM Fix Central to search for, download and apply the following fixpacks for your version of product:

  • All 8.0.0.x -> 8.0.0.4 * All 8.0.1.x ->8.0.1.5 * All 8.5.0.x ->8.5.0.3 * All 8.5.1.x ->8.5.1.4 * All 8.6.0.x ->8.6.0.3

Workarounds and Mitigations

None

EPSS

0.016

Percentile

87.6%

Related for F8E21E22BBD59DA4E36EFB1691DE04923003ACD8B571119B3561711837177CCB