IBM Support

Security vulnerabilities in Rational Software Architect Design Manager and Rational Rhapsody Design Manager (CVE-2014-0947 , CVE-2014-0948 )

Security Bulletin


Summary

Security vulnerabilities have been identified in Rational Software Architect Design Manager and Rational Rhapsody Design Manager. The exposure would allow a remote attacker to execute arbitrary code on the server.

Vulnerability Details

Subscribe to My Notifications to be notified of important product support alerts like this.
  • Follow this link for more information (requires login with your IBM ID)


CVE ID: CVE-2014-0947

Description
: An unidentified vulnerability in Rational Software Architect Design Manager allows an authenticated user to provision an arbitrary update site into the Design Manager server code. This vulnerability exists only in Rational Software Architect Design Manager version 4.0.6.

CVSS Base Score:
6
CVSS Temporal Score:
See https://exchange.xforce.ibmcloud.com/vulnerabilities/92620 for the current score
CVSS Environmental Score*:
Undefined
CVSS Vector:
(AV:N/AC:M/Au:S/C:P/I:P/A:P)

CVE ID: CVE-2014-0948

Description
: An unidentified vulnerability in Rational Software Architect Design Manager and Rational Rhapsody Design Manager allows a remote attacker to upload malicious .zip files, and arbitrarily plant attack files on the system.

CVSS Base Score:
6
CVSS Temporal Score:
See https://exchange.xforce.ibmcloud.com/vulnerabilities/92621 for the current score
CVSS Environmental Score*:
Undefined
CVSS Vector:
(AV:N/AC:M/Au:S/C:P/I:P/A:P)

Affected Products and Versions

Rational Software Architect Design Manager 3.0, 3.0.0.1, 3.0.1
Rational Software Architect Design Manager 4.0 - 4.0.6
Rational Rhapsody Design Manager 3.0, 3.0.0.1, 3.0.1
Rational Rhapsody Design Manager 4.0 - 4.0.6

Remediation/Fixes

For Rational Software Architect Design Manager versions 3.0 - 4.0.6:

For Rhapsody Design Manager versions 3.0 - 4.0.6:
For the 3.x releases of Rational Software Architect Design Manager and Rhapsody Design Manager, customers who cannot upgrade to 4.0.7 or 5.0, please contact IBM support for guidance.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

None

Change History

* 18 July 2014: Original copy published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Internal Use Only

Here are more complete descriptions of the vulnerabilities. Do not give out details without a Non-disclosure agreement.

CVE ID: CVE-2014-0947

Description
: The 'File->Import Profiles from Update Site' operation in Rational Software Architect Design Manager allows an authenticated user to provision an arbitrary update site into the Design Manager server code

RSA DM PSIRT# 1631 Record # 35039

CVE ID: CVE-2014-0948
Description: The File->Import operation in Rational Software Architect Design Manager and Rational Rhapsody Design Manager allows a remote attacker to upload malicious .zip files, and arbitrarily plant attack files on the system.

RSA DM PSIRT# 1625 Record # 34811
Rhapsody DM PSIRT# 1625 Record # 34810

[{"Product":{"code":"SSRMY8","label":"Rational Software Architect Design Manager"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"General Information","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"3.0;3.0.0.1;3.0.1;4.0;4.0.1;4.0.2;4.0.3;4.0.4;4.0.5;4.0.6","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}},{"Product":{"code":"SSRNEV","label":"Rational Rhapsody Design Manager"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":" ","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"3.0;3.0.0.1;3.0.1;4.0;4.0.1;4.0.2;4.0.3;4.0.4;4.0.5;4.0.6","Edition":"","Line of Business":{"code":"LOB59","label":"Sustainability Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21678323