Release date:
Updated on:
Affected Systems:
IBM Rational Build Forge 7.x
Description:
--------------------------------------------------------------------------------
IBM Rational Build Forge is an automated process execution software that helps customers Build, test, and release automated software. It is also a continuous Integration Server.
IBM Rational Build Forge has a vulnerability in security settings. Malicious users can exploit this vulnerability to leak sensitive information.
This vulnerability occurs because the Web application does not have the "EditSecurity" permission when performing some operations. You can export the key file from the security sub-menu.
<* Source: vendor
Link: https://www.ibm.com/support/docview.wss? Uid = swg1PM38058
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ers.ibm.com/