Security Bulletin
Summary
Security vulnerabilities have been identified in Rational Software Architect Design Manager and Rational Rhapsody Design Manager. The exposure would allow a remote attacker to execute arbitrary code on the server.
Vulnerability Details
Subscribe to My Notifications to be notified of important product support alerts like this.
|
CVE ID: CVE-2014-0947
Description: An unidentified vulnerability in Rational Software Architect Design Manager allows an authenticated user to provision an arbitrary update site into the Design Manager server code. This vulnerability exists only in Rational Software Architect Design Manager version 4.0.6.
CVSS Base Score: 6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/92620 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:P)
CVE ID: CVE-2014-0948
Description: An unidentified vulnerability in Rational Software Architect Design Manager and Rational Rhapsody Design Manager allows a remote attacker to upload malicious .zip files, and arbitrarily plant attack files on the system.
CVSS Base Score: 6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/92621 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:P)
Affected Products and Versions
Rational Software Architect Design Manager 3.0, 3.0.0.1, 3.0.1
Rational Software Architect Design Manager 4.0 - 4.0.6
Rational Rhapsody Design Manager 3.0, 3.0.0.1, 3.0.1
Rational Rhapsody Design Manager 4.0 - 4.0.6
Remediation/Fixes
For Rational Software Architect Design Manager versions 3.0 - 4.0.6:
- Upgrade to Rational Software Architect Design Manager 4.0.7
- Upgrade to Rational Software Architect Design Manager 5.0
or
- Upgrade to Rational Rhapsody Design Manager 4.0.7
- Upgrade to Rational Rhapsody Design Manager 5.0
or
For the 3.x releases of Rational Software Architect Design Manager and Rhapsody Design Manager, customers who cannot upgrade to 4.0.7 or 5.0, please contact IBM support for guidance.
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Acknowledgement
None
Change History
* 18 July 2014: Original copy published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Internal Use Only
Here are more complete descriptions of the vulnerabilities. Do not give out details without a Non-disclosure agreement.
CVE ID: CVE-2014-0947
Description: The 'File->Import Profiles from Update Site' operation in Rational Software Architect Design Manager allows an authenticated user to provision an arbitrary update site into the Design Manager server code
RSA DM PSIRT# 1631 Record # 35039
CVE ID: CVE-2014-0948
Description: The File->Import operation in Rational Software Architect Design Manager and Rational Rhapsody Design Manager allows a remote attacker to upload malicious .zip files, and arbitrarily plant attack files on the system.
RSA DM PSIRT# 1625 Record # 34811
Rhapsody DM PSIRT# 1625 Record # 34810
Was this topic helpful?
Document Information
Modified date:
16 June 2018
UID
swg21678323