Vulnerability Description
The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information or modify network traffic via a crafted certificate. IBM X-Force ID: 106715.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Rational Clearcase | >= 7.1, <= 7.1.2.16 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21976566Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/106715VDB EntryVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21976566Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/106715VDB EntryVendor Advisory
FAQ
What is CVE-2015-5039?
CVE-2015-5039 is a vulnerability with a CVSS score of 7.4 (HIGH). The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from...
How severe is CVE-2015-5039?
CVE-2015-5039 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5039?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Rational Clearcase.