IBM Support

Security Bulletin: Critical security vulnerability in Jazz Team Server affecting Rational Software Architect Design Manager and Rational Rhapsody Design Manager (CVE-2014-0862)

Security Bulletin


Summary

A high risk vulnerability has been identified in the Jazz Team Server affecting some applications which use the Jazz Team Server. Rational Software Architect Design Manager and Rational Rhapsody Design Manager are affected applications. The exposure would allow a remote attacker to execute arbitrary code on the server.

Vulnerability Details

Subscribe to My Notifications to be notified of important product support alerts like this.
  • Follow this link for more information (requires login with your IBM ID)


CVE ID: CVE-2014-0862

Description
: An unspecified vulnerability in Jazz Team Server allows remote attackers to execute arbitrary code on the server. The potentially malicious code being executed could compromise the integrity, confidentiality and availability of the server.

CVSS Base Score:
10
CVSS Temporal Score:
See https://exchange.xforce.ibmcloud.com/vulnerabilities/90895 for the current score
CVSS Environmental Score*:
Undefined
CVSS Vector:
(AV:N/AC:L/Au:N/C:C/I:C/A:C)

Affected Products and Versions

Rational Software Architect Design Manager 3.0, 3.0.0.1, 3.0.1
Rational Software Architect Design Manager 4.0 - 4.0.5
Rational Rhapsody Design Manager 3.0, 3.0.0.1, 3.0.1
Rational Rhapsody Design Manager 4.0 - 4.0.5

Remediation/Fixes

For the 4.x releases of Rational Software Architect Design Manager upgrade to version 4.0.6:
Rational Software Architect Design Manager 4.0.6

For the 4.x releases of Rational Rhapsody Design Manager upgrade to version 4.0.6:
Rational Rhapsody Design Manager 4.0.6

If you are unable to upgrade, apply the workaround listed below. If you have questions, contact IBM support for additional details on the fix.

For the 3.x releases of Rational Software Architect Design Manager and Rational Rhapsody Design Manager, apply the workaround listed below. If you have questions, contact IBM support for additional details on the fix.

Workarounds and Mitigations

Refer to the instructions in the following technote (as described for the Rational CLM products) to remove this vulnerability.

How to block the Install URL

Note: In addition to the list of .war files in the above technote, you must also apply the steps for these additional files:

  • dm.war
  • rsadm.war (Rational Software Architect Design Manager only)

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

These vulnerabilities were reported by Insomnia Security.

Change History

* 24 April 2014: Original copy published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSRMY8","label":"Rational Software Architect Design Manager"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"General Information","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"3.0;3.0.0.1;3.0.1;4.0;4.0.1;4.0.2;4.0.3;4.0.4;4.0.5","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}},{"Product":{"code":"SSRNEV","label":"Rational Rhapsody Design Manager"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":" ","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"3.0;3.0.0.1;3.0.1;4.0;4.0.1;4.0.2;4.0.3;4.0.4;4.0.5","Edition":"","Line of Business":{"code":"LOB59","label":"Sustainability Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21671357