IBM Security Bulletin: XML vulnerabilities in ClearQuest (CVE-2016-0729, CVE-2016-4463)

IBM Rational ClearQuest is vulnerable to XML parsing attacks. These attacks could cause a denial of service or execution of code.

CVE(s): CVE-2016-0729, CVE-2016-4463

Affected product(s) and affected version(s):

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2f8f9Rv
X-Force Database: http://ift.tt/297OoIU
X-Force Database: http://ift.tt/2b5BVXc

The post IBM Security Bulletin: XML vulnerabilities in ClearQuest (CVE-2016-0729, CVE-2016-4463) appeared first on IBM PSIRT Blog.

ClearQuest versionStatus
9.0.1, 9.0.1.1Not Affected
9.0 through 9.0.0.4Affected
8.0.1 through 8.0.1.14Affected
8.0 through 8.0.0.21Affected
7.1.2 through 7.1.2.19 (all fix packs)Affected


from IBM Product Security Incident Response Team http://ift.tt/2jrEh72