IBM Support

IBM Engineering Lifecycle Management - Security vulnerabilities identified by third party scanning tools

General Page

This document describes the IBM Engineering Lifecycle Management (ELM) support policy for security vulnerabilities identified by third party scanning tools.
Background 
IBM performs security vulnerability code scanning on all new major software product releases as part of its Secure Engineering practices. We do regular testing and scanning for the latest security vulnerabilities that may pose a threat to components of the ELM product.  See SPbD@IBM in the IBM Trust Center for more information.
Support 

We will accept Support Cases for investigating critical and high severity vulnerabilities identified by third party scanning tools.

Before opening a support case, it is expected that the customer will:

  • Review and triage their third party scanning tool vulnerability reports to identify those items that are true positives and truly critical/high severity.
  • Check that the vulnerability is not already addressed in a newer version of the ELM product.
  • Describe the steps necessary to re-produce each vulnerability. These are the steps that cause the vulnerability to manifest in ELM, not the steps to run the scan.
  • Identify a CVE number or link to published details related to each vulnerability

The CVE number or link lets us check the specific issue against solutions already in place. It also helps when we need to engage product development for assistance in creating a solution specific to that issue (CVE number). Without a CVE number it is difficult for support to provide a specific solution to a vulnerability. 

Open a single support case for each critical or high severity vulnerability and provide the information listed above. This will provide clarity for you and the Support organization when identifying a resolution to the issue.

[{"Type":"MASTER","Line of Business":{"code":"LOB59","label":"Sustainability Software"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSF34G","label":"IBM Engineering Lifecycle Management Suite"},"ARM Category":[{"code":"a8m50000000L2CkAAK","label":"ELM-\u003ESecurity"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
17 July 2024

UID

ibm17156368