Security Bulletin: Potential security vulnerability in CLM 3.x and CLM 4.x products for the Oracle June 2012 CPU (CVE-2012-1713)

Flash (Alert)


Abstract

The v3 and v4 releases of the CLM products (Rational Quality Manager, Rational Team Concert, and Rational Requirements Composer) are shipped with an IBM Java that is based on the Oracle Java. Oracle has released a June 2012 critical patch updates (CPU) which contain security vulnerability fixes and the IBM Java is affected.

Content

VULNERABILITY DETAILS

CVE ID: CVE-2012-1713

DESCRIPTION:

There is a vulnerability in the Java Runtime Environment component of Java SE (subcomponent: 2D).

This applies to client and server deployments of Java. This vulnerability can be exploited through untrusted Java Web Start applications and untrusted Java applets. It can also be exploited by supplying data to APIs in the specified Component without using untrusted Java Web Start applications or untrusted Java applets, such as through a web service.

CVSS Base Score: 10
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/76239 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C)

REMEDIATION: The recommended solution is to apply the fix for each named product as soon as practical. Please see below for information on the fixes available.

Fix:

For the affected products, the 3.0.1.5 fix pack and the 4.0.1 releases include an updated IBM Java version which addresses these security issues.

Rational Team Concert 3.0.1.5
Rational Quality Manager 3.0.1.5
Rational Requirements Composer 3.0.1.5

Rational Team Concert 4.0.1
Rational Quality Manager 4.0.1
Rational Requirements Composer 4.0.1

Workaround:

None.

REFERENCES:

Cross reference information
Segment Product Component Platform Version Edition
Software Development Rational Team Concert Not Applicable 3.0.1, 3.0.1.1, 3.0.1.2, 3.0.1.3, 3.0.1.4, 4.0, 4.0.0.1
Software Development Rational Requirements Composer Not Applicable 3.0.1, 3.0.1.1, 3.0.1.2, 3.0.1.3, 3.0.1.4, 4.0, 4.0.0.1

Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

Rational Quality Manager

Software version:

3.0.1, 3.0.1.1, 3.0.1.2, 3.0.1.3, 3.0.1.4, 4.0, 4.0.0.1

Operating system(s):

AIX, Linux, Solaris, Windows, z/OS

Reference #:

1615854

Modified date:

2012-11-27

Translate my page

Machine Translation

Content navigation