CVE-2008-5330: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATHINFO of a URI associated with a VOB page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5330?
CVE-2008-5330 is rated as medium severity due to its potential for remote code execution via cross-site scripting.
How do I fix CVE-2008-5330?
To remediate CVE-2008-5330, upgrade to IBM Rational ClearCase versions 7.0.0.4 or higher, or 7.0.1.3 or higher.
What software is affected by CVE-2008-5330?
CVE-2008-5330 affects several versions of IBM Rational ClearQuest, particularly those before 7.0.1.3.
What type of vulnerability is CVE-2008-5330?
CVE-2008-5330 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2008-5330 lead to data theft?
Yes, CVE-2008-5330 can allow attackers to inject scripts that may lead to data theft or session hijacking.