First published: Fri Dec 05 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational ClearQuest | =7.0.1.1 | |
IBM Rational ClearQuest | =7.0.0.1 | |
IBM Rational ClearQuest | =7.0.0.2 | |
IBM Rational ClearQuest | =7.0.0.0 | |
IBM Rational ClearQuest | =7.0.0.3 | |
IBM Rational ClearQuest | =7.0.1 | |
IBM Rational ClearQuest | =7.0.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5330 is rated as medium severity due to its potential for remote code execution via cross-site scripting.
To remediate CVE-2008-5330, upgrade to IBM Rational ClearCase versions 7.0.0.4 or higher, or 7.0.1.3 or higher.
CVE-2008-5330 affects several versions of IBM Rational ClearQuest, particularly those before 7.0.1.3.
CVE-2008-5330 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2008-5330 can allow attackers to inject scripts that may lead to data theft or session hijacking.