Medium Severity

IBM Security Bulletin: Security Vulnerabilities in IBM® Java SDK affect multiple IBM Rational products based on IBM Jazz technology Oct 2018 CPU

Share this post:

There are multiple vulnerabilities in IBM® SDK Java Technology Edition, Version 1.7 and 1.8 that are used by IBM Jazz Team Server affecting the following IBM Jazz Team Server based Applications: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM). These issues were disclosed as part of the IBM Java SDK updates in October 2018.

CVE(s): CVE-2018-3139, CVE-2018-3180

Affected product(s) and affected version(s):

Rational Collaborative Lifecycle Management 5.0 – 6.0.6

Rational Quality Manager 5.0 – 5.0.2
Rational Quality Manager 6.0 – 6.0.6

Rational Team Concert 5.0 – 5.0.2
Rational Team Concert 6.0 – 6.0.6

Rational DOORS Next Generation 5.0 – 5.0.2
Rational DOORS Next Generation 6.0 – 6.0.6

Rational Engineering Lifecycle Manager 5.0 – 5.0.2
Rational Engineering Lifecycle Manager 6.0 – 6.0.6

Rational Rhapsody Design Manager 5.0 – 5.0.2
Rational Rhapsody Design Manager 6.0 – 6.0.6

Rational Software Architect Design Manager 5.0 – 5.0.2
Rational Software Architect Design Manager 6.0 – 6.0.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10744823
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/151455
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/151497

More stories

IBM Security Bulletin: IBM Dynamic System Analysis (DSA) Preboot is affected by vulnerabilities in cURL (CVE-2018-16840 CVE-2018-16842)

Apr 24, 2019 9:01 am EDT | Medium Severity

IBM Dynamic System Analysis (DSA) Preboot has addressed the following vulnerabilities in cURL. CVE(s): CVE-2018-16840, CVE-2018-16842 Affected product(s) and affected version(s): Product Affected Version IBM Dynamic System Analysis (DSA) Preboot 9.6 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10882106X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152299X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152300 ...read more


IBM Security Bulletin: API Connect V5 is impacted by vulnerabilities in Bootstrap (CVE-2018-14040 CVE-2018-14041 CVE-2018-14042)

Apr 24, 2019 9:01 am EDT | Medium Severity

IBM API Connect has addressed the following vulnerability. CVE(s): CVE-2018-14042, CVE-2018-14041, CVE-2018-14040 Affected product(s) and affected version(s): Affected IBM API Management Affected Versions IBM API Connect 5.0.0.0-5.0.8.5 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10880955X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146466X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146467X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146468 ...read more


IBM Security Bulletin: IBM InfoSphere Data Quality Exception Console is affected by a Reflected XSS (Cross-Site Scripting) vulnerability

Apr 24, 2019 9:01 am EDT | Medium Severity

A Reflected XSS (Cross-Site Scripting) vulnerability was addressed by IBM InfoSphere Data Quality Exception Console. CVE(s): CVE-2019-4238 Affected product(s) and affected version(s): The following products, running on all supported platforms, are affected: IBM InfoSphere Data Quality Exception Console: versions 11.3, 11.5, and 11.7 IBM InfoSphere Information Server on Cloud: version 11.5, and 11.7 Refer to ...read more