First published: Fri Aug 08 2008(Updated: )
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational ClearQuest | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3550 has a medium severity rating due to its potential for information disclosure through user input manipulation.
To fix CVE-2008-3550, it is recommended to update IBM Rational ClearQuest to a version that addresses this vulnerability.
CVE-2008-3550 can expose potentially sensitive information from the page source code through a crafted login request.
CVE-2008-3550 specifically affects IBM Rational ClearQuest version 7.0.1.
Yes, CVE-2008-3550 may be considered related to a cross-site scripting (XSS) vulnerability due to its exploitation method involving user input.