Skip to main content


IC56219: Security vulnerabilities exist within the shipped version if IHS shipped with ClearCase Web Interface

 

APAR status

  • Closed as program error.

Error description

  • Security vulnerabilities exist within the shipped version of IHS
    for the ClearCase Web Interface:  We presently ship the followi
    ng IHS, including patches, with the latest versions of ClearCase
     7.0.0.0, 7.0.0.1 and 7.0.1:
    
    ./apachectl -v
    Server version: IBM_HTTP_Server/6.0.2.13 Apache/2.0.47
    Server built:   Jun  8 2006 21:00:25
    
    Workaround:
    Contact IBM Rational Support
    
    IHS server 6.0:  The latest update includes all vulnerabilities
    addressed with the exception of two. And there are work-a-rounds
     for those two.  Please download the latest IHS 6.0.2.25 from th
    e following URL:
       http://www-1.ibm.com/support/docview.wss?rs=177?uid=swg270051
    98#60
    
    Exceptions (manually apply fix as recommended):
       CVE-2007-5000
       CVE-2007-6388
    

Local fix

Problem summary

  • Security vulnerabilities exist in the IBM HTTP Server 6.0.2
    shipped with ClearCase 7.0 or 7.0.1.
    

Problem conclusion

  • A fix is available in Fix Pack 27 for IHS 6.0.2 and
    ClearCase version 7.0.1.3 or later.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IC56219

  • Reported component name

    RATL CLEARCASE

  • Reported component ID

    5724F1400

  • Reported release

    ALL

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2008-04-14

  • Closed date

    2009-01-07

  • Last modified date

    2009-01-07

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    RATL CLEARCASE

  • Fixed component ID

    5724F1400

Applicable component levels

  • RALL PSN

       UP

Copyright and trademark information

IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.

Rate this page

Please take a moment to complete this form to help us better serve you.

This material provides me with the information I need.






This material is clear and easy to understand.






Did the information help you to achieve your goal?

What updates, improvements, or related information would you like to see in this document?

Your response will be used to improve our document content. Requests for assistance, if applicable, should be submitted through your normal support channel as we cannot respond from this site.


Input the verification number to submit feedback:



Maintenance Window

Unscheduled Maintenance Window

There is no unscheduled maintenance scheduled at this time.

Document information

Product categories:

Software

Software Development

Change, Configuration, & Release Management

Rational ClearCase


Software version:

ALL


Reference #:

IC56219


IBM Group:

Software Group


Modified date:

2009-01-07

Translate my page