CVE-2008-3550: Infoleak
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3550?
CVE-2008-3550 has a medium severity rating due to its potential for information disclosure through user input manipulation.
How do I fix CVE-2008-3550?
To fix CVE-2008-3550, it is recommended to update IBM Rational ClearQuest to a version that addresses this vulnerability.
What information can be exposed by CVE-2008-3550?
CVE-2008-3550 can expose potentially sensitive information from the page source code through a crafted login request.
Which version of IBM Rational ClearQuest is affected by CVE-2008-3550?
CVE-2008-3550 specifically affects IBM Rational ClearQuest version 7.0.1.
Is CVE-2008-3550 a cross-site scripting vulnerability?
Yes, CVE-2008-3550 may be considered related to a cross-site scripting (XSS) vulnerability due to its exploitation method involving user input.