First published: Mon Mar 20 2017(Updated: )
IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server. IBM Reference #: 1999960.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rhapsody Design Manager | =4.0 | |
IBM Rhapsody Design Manager | =4.0.1 | |
IBM Rhapsody Design Manager | =4.0.2 | |
IBM Rhapsody Design Manager | =4.0.3 | |
IBM Rhapsody Design Manager | =4.0.4 | |
IBM Rhapsody Design Manager | =4.0.5 | |
IBM Rhapsody Design Manager | =4.0.6 | |
IBM Rhapsody Design Manager | =4.0.7 | |
IBM Rhapsody Design Manager | =5.0 | |
IBM Rhapsody Design Manager | =5.0.1 | |
IBM Rhapsody Design Manager | =5.0.2 | |
IBM Rhapsody Design Manager | =6.0 | |
IBM Rhapsody Design Manager | =6.0.1 | |
IBM Rhapsody Design Manager | =6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-8973 is classified based on its potential impact on the system, which could allow authenticated users to upload malicious files.
To fix CVE-2016-8973, it is recommended to apply the latest patches provided by IBM for the affected versions of Rhapsody DM.
CVE-2016-8973 affects IBM Rhapsody DM versions 4.0, 4.0.1 through 4.0.7, 5.0 through 5.0.2, and 6.0 through 6.0.2.
Authenticated users of IBM Rhapsody DM who have access to upload files are impacted by CVE-2016-8973.
Yes, CVE-2016-8973 is an authenticated vulnerability that requires user authentication to exploit.