IBM RTC Improper Restriction of XML External Entity Reference Vulnerability - CVE-2016-0284
The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational Quality Manager 3.0.1.6 before iFix8 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational Team Concert 3.0.1.6 before iFix8 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational DOORS Next Generation 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11 5.0 before 5.0.2 iFix18 and 6.0 before 6.0.2 iFix5 allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference related to an XML External Entity (XXE) issue.