IBM Support

Changes to Engineering Lifecycle Management related to Server-Side Request Forgery (SSRF) vulnerabilities.

How To


Summary

ELM 7.0.2 iFix004, ELM 7.0.1 iFix009, CLM 6.0.6.1 iFix018, and CLM 6.0.6 iFix022 changed the behavior of all OpenSocial gadgets and RSS feeds that fetch content from an external service or location. The change was made to decrease the SSRF vulnerability by allowing communication to sites explicitly listed in the "allowlist." Although reducing the security vulnerability of ELM/CLM, this change can prevent some widgets from functioning when these interim fixes are applied.

Document Location

Worldwide

[{"Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSPRJQ","label":"IBM Engineering Lifecycle Management Base"},"ARM Category":[{"code":"a8m50000000L2CkAAK","label":"Continuous Engineering-\u003ESecurity"},{"code":"a8m0z000000CbPxAAK","label":"Jazz Team Server-\u003ESecurity Vulnerabilities"},{"code":"a8m50000000CjLHAA0","label":"Test Management-\u003ESecurity and Authentication"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0.1;7.0.2;and future releases","Type":"MASTER"},{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSUVLZ","label":"IBM Engineering Requirements Management DOORS Next"},"ARM Category":[{"code":"a8m50000000L2CkAAK","label":"Continuous Engineering-\u003ESecurity"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0.6;7.0.1;7.0.2;and future releases"},{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSUVV6","label":"IBM Engineering Test Management"},"ARM Category":[{"code":"a8m50000000CjLHAA0","label":"Test Management-\u003ESecurity and Authentication"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0.1;7.0.2;and future releases"},{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSUC3U","label":"IBM Engineering Workflow Management"},"ARM Category":[{"code":"a8m50000000CjdlAAC","label":"Workflow Management-\u003ESecurity"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0.1;7.0.2;and future releases"},{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSJJ9R","label":"Rational DOORS Next Generation"},"ARM Category":[{"code":"a8m0z000000CbPxAAK","label":"Jazz Team Server-\u003ESecurity Vulnerabilities"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0.0;and future releases"},{"Type":"MASTER","Line of Business":{"code":"LOB59","label":"Sustainability Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSR27Q","label":"Rational Quality Manager"},"ARM Category":[{"code":"a8m50000000CjLHAA0","label":"Test Management-\u003ESecurity and Authentication"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0.0;and future releases"},{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSCP65","label":"Rational Team Concert"},"ARM Category":[{"code":"a8m0z000000CbPxAAK","label":"Jazz Team Server-\u003ESecurity Vulnerabilities"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0.0;and future releases"},{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSYMRC","label":"Rational Collaborative Lifecycle Management"},"ARM Category":[{"code":"a8m0z000000CbPxAAK","label":"Jazz Team Server-\u003ESecurity Vulnerabilities"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0.6;and future releases"},{"Product":{"code":"SSF34G","label":"IBM Engineering Lifecycle Management Suite"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":" ","Platform":[{"code":"","label":""}],"Version":"","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
24 October 2024

UID

ibm16466981