IBM Security Bulletin: XML vulnerabilities in ClearQuest (CVE-2016-0729, CVE-2016-4463)
IBM Rational ClearQuest is vulnerable to XML parsing attacks. These attacks could cause a denial of service or execution of code.
CVE(s): CVE-2016-0729, CVE-2016-4463
Affected product(s) and affected version(s):
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2f8f9Rv
X-Force Database: http://ift.tt/297OoIU
X-Force Database: http://ift.tt/2b5BVXc
The post IBM Security Bulletin: XML vulnerabilities in ClearQuest (CVE-2016-0729, CVE-2016-4463) appeared first on IBM PSIRT Blog.
ClearQuest version | Status |
9.0.1, 9.0.1.1 | Not Affected |
9.0 through 9.0.0.4 | Affected |
8.0.1 through 8.0.1.14 | Affected |
8.0 through 8.0.0.21 | Affected |
7.1.2 through 7.1.2.19 (all fix packs) | Affected |
from IBM Product Security Incident Response Team http://ift.tt/2jrEh72