IBM Security Bulletin: Security vulnerabilities in Apache Tomcat affects multiple IBM Rational products based on IBM’s Jazz technology

The Jazz Team Server is shipped with or supports versions of the Apache Tomcat web server which contain security vulnerabilities that could potentially impact the following IBM Rational products deployed on Apache Tomcat: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rhapsody Design Manager (Rhapsody DM), Rational Software Architect Design Manager (RSA DM), Rational Team Concert (RTC), and Rational Quality Manager (RQM).

CVE(s): CVE-2016-6816, CVE-2016-8735

Affected product(s) and affected version(s):

Rational Collaborative Lifecycle Management 4.0 – 6.0.3

Rational Quality Manager 4.0 – 4.0.7
Rational Quality Manager 5.0 – 5.0.2
Rational Quality Manager 6.0 – 6.0.3

Rational Team Concert 4.0 – 4.0.7
Rational Team Concert 5.0 – 5.0.2
Rational Team Concert 6.0 – 6.0.3

Rational DOORS Next Generation 4.0.1 – 4.0.7
Rational DOORS Next Generation 5.0 – 5.0.2
Rational DOORS Next Generation 6.0 – 6.0.3

Rational Engineering Lifecycle Manager 4.0.3 – 4.0.7
Rational Engineering Lifecycle Manager 5.0 – 5.0.2
Rational Engineering Lifecycle Manager 6.0 – 6.0.3

Rational Rhapsody Design Manager 4.0 – 4.0.7
Rational Rhapsody Design Manager 5.0 – 5.0.2
Rational Rhapsody Design Manager 6.0 – 6.0.3

Rational Software Architect Design Manager 4.0 – 4.0.7
Rational Software Architect Design Manager 5.0 – 5.0.2
Rational Software Architect Design Manager 6.0 – 6.0.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2jfdD01
X-Force Database: http://ift.tt/2iIaaqs
X-Force Database: http://ift.tt/2j4D3cR



from IBM Product Security Incident Response Team http://ift.tt/2jExlPk