IBM Security Bulletin: A security vulnerability in GSKit affects IBM Rational ClearQuest (CVE-2016-2183)

The GSKit that is shipped with IBM Rational ClearQuest contains a security vulnerability. IBM Rational ClearQuest has addressed the applicable CVE.

CVE(s): CVE-2016-2183

Affected product(s) and affected version(s):

Rational ClearQuest versions 7.1.2 through 7.1.2.19, 8.0 through 8.0.0.21, 8.0.1 through 8.0.1.14, and 9.0 through 9.0.0.4:

You are vulnerable if you configure Rational ClearQuest to use LDAP authentication with secure sockets connections.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2jscXWv
X-Force Database: http://ift.tt/2dR3VyC

The post IBM Security Bulletin: A security vulnerability in GSKit affects IBM Rational ClearQuest (CVE-2016-2183) appeared first on IBM PSIRT Blog.

ClearQuest versionStatus
9.0.1, 9.0.1.1Not Affected
9.0 through 9.0.0.4Affected
8.0.1 through 8.0.1.14Affected
8.0 through 8.0.0.21Affected
7.1.2 through 7.1.2.19 (all fix packs)Affected


from IBM Product Security Incident Response Team http://ift.tt/2jsEAi8