First published: Tue Sep 20 2005(Updated: )
Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (XSS).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational ClearQuest | =6.10 | |
IBM Rational ClearQuest | =6.14 | |
IBM Rational ClearQuest | =5.00 | |
IBM Rational ClearQuest | =5.20 | |
IBM Rational ClearQuest | =6.13 | |
IBM Rational ClearQuest | =6.12 | |
IBM Rational ClearQuest | =6.15 | |
IBM Rational ClearQuest | =6.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2994 is considered a high severity vulnerability due to potential remote code execution via XML Style Sheets.
To fix CVE-2005-2994, upgrade IBM Rational ClearQuest to a version that has addressed this vulnerability, such as SR5 or later.
CVE-2005-2994 affects IBM Rational ClearQuest versions 5.00, 5.20, 6.00, 6.10, 6.12, 6.13, 6.14, and 6.15.
Yes, CVE-2005-2994 can be exploited remotely by attackers through the web client of the affected IBM Rational ClearQuest versions.
Yes, a patch is included in later service releases of IBM Rational ClearQuest after SR5.