CVE-2008-5329: High severity ibm rational clearquest vulnerability
ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary database by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in a jtl.properties file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5329?
CVE-2008-5329 is considered to have a medium severity because it allows remote servers to manipulate client submissions and database changes.
How do I fix CVE-2008-5329?
To fix CVE-2008-5329, limit the JTLRMIREGISTRYSERVERS entries in the jtl.properties file to trusted server identifiers.
What versions of IBM Rational ClearQuest are affected by CVE-2008-5329?
CVE-2008-5329 affects IBM Rational ClearQuest versions 7.0.0.0 to 7.1 inclusive.
Can CVE-2008-5329 be exploited remotely?
Yes, CVE-2008-5329 can be exploited remotely, allowing attackers to redirect client submissions to arbitrary databases.
Is there a patch available for CVE-2008-5329?
IBM provides updates to address CVE-2008-5329, and users should ensure they are running the latest version of ClearQuest.