CVE-2014-3090: Medium severity ibm rational clearcase vulnerability
IBM Rational ClearCase 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3090?
CVE-2014-3090 has a medium severity rating due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2014-3090?
To fix CVE-2014-3090, upgrade to IBM Rational ClearCase versions 7.1.2.15, 8.0.0.12, or 8.0.1.5 or later.
What systems are affected by CVE-2014-3090?
CVE-2014-3090 affects IBM Rational ClearCase versions 7.1 through 8.0.1.4.
What type of vulnerability is CVE-2014-3090?
CVE-2014-3090 is a denial of service vulnerability caused by processing a crafted XML document.
Can CVE-2014-3090 be exploited remotely?
Yes, CVE-2014-3090 can be exploited remotely by attackers sending specially crafted XML documents.