Vulnerability Description
Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9, 7.1.2 through 7.1.2.13, 8.0.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92623.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Rational Clearquest | >= 7.1.1, <= 7.1.1.9 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21675164PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92623VDB EntryVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21675164PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92623VDB EntryVendor Advisory
FAQ
What is CVE-2014-0950?
CVE-2014-0950 is a vulnerability with a CVSS score of 7.1 (HIGH). Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational...
How severe is CVE-2014-0950?
CVE-2014-0950 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0950?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Rational Clearquest.