IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Rational ClearQuest (CVE-2017-1289)

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 6, 7, and 8, which are used by IBM Rational ClearQuest. These issues were disclosed as part of the IBM Java SDK updates in April 2017.

CVE(s): CVE-2017-1289

Affected product(s) and affected version(s):

IBM Rational ClearQuest, versions 7.1, 7.1.1, 7.1.2, 8.0, 8.0.1 and 9.0 in the following components:

  • ClearQuest Web/CQ OSLC server/CM Server component.
  • ClearQuest Eclipse clients.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2xngLxC
X-Force Database: http://ift.tt/2pvwR1f

The post IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Rational ClearQuest (CVE-2017-1289) appeared first on IBM PSIRT Blog.

ClearQuest versionStatus
9.0.1Affected
9.0 through 9.0.0.4Affected
8.0.1 through 8.0.1.14Affected
8.0 through 8.0.0.21Affected
7.1.2 through 7.1.2.19 (all fix packs)Affected


from IBM Product Security Incident Response Team http://ift.tt/2xnrCrh