Security Bulletin: Vulnerabilities in ClearCase OpenSSL Component (CVE-2013-0169, CVE-2012-2686, CVE-2013-0166)

Flash (Alert)


Abstract

The OpenSSL component shipped as a part of IBM Rational ClearCase has issued a security advisory. This component is used in making SSL connections in the base CC/CQ integration and in making SSL connections via user Perl modules. On the UNIX/Linux platforms, OpenSSL can also be used by the UCM/CQ integration.

Content

Subscribe to My Notifications to be notified of important product support alerts like this.
  • Follow this link for more information (requires login with your IBM ID)

VULNERABILITY DETAILS:

CVE ID: CVE-2013-0169
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/81902
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

DESCRIPTION:
This vulnerability is listed in the OpenSSL security advisory located at
http://www.openssl.org/news/secadv_20130204.txt

CVE ID: CVE-2013-0166
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/81904 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

DESCRIPTION:
This vulnerability is listed in the OpenSSL security advisory located at
http://www.openssl.org/news/secadv_20130204.txt

CVE ID: CVE-2012-2686
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/81903 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

DESCRIPTION:
This vulnerability is listed in the OpenSSL security advisory located at
http://www.openssl.org/news/secadv_20130204.txt

AFFECTED VERSIONS:
Rational ClearCase versions prior to v8.0.0.7, or v7.1.2.11

REMEDIATION:
The solution is to upgrade to a version of ClearCase that has a newer OpenSSL component that corrects these vulnerabilities. Please see below for information on the fixes available.

Fix:


Workaround(s):
None.

Mitigation(s):
None.

REFERENCES:

RELATED INFORMATION:
ACKNOWLEDGEMENT: None

CHANGE HISTORY: June 26, 2013 Original Copy Published

*The CVSS Environment Score is customer environment specific and will ultimately impact
the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their
environments by accessing the links in the References section of this Flash.

Note: According to the Forum of Incident Response and Security Teams (FIRST), the
Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to
convey vulnerability severity and help to determine urgency and priority of response." IBM
PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND,
INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING
THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

Rational ClearCase
Perl: ratlperl

Software version:

7.1.2, 7.1.2.1, 7.1.2.2, 7.1.2.3, 7.1.2.4, 7.1.2.5, 7.1.2.6, 7.1.2.7, 7.1.2.8, 7.1.2.9, 7.1.2.10, 8.0, 8.0.0.1, 8.0.0.2, 8.0.0.3, 8.0.0.4, 8.0.0.5, 8.0.0.6

Operating system(s):

AIX, HP-UX, IRIX, Linux, Mac OS X, Solaris, Windows

Reference #:

1641524

Modified date:

2013-11-21

Translate my page

Machine Translation

Content navigation