CVE-2014-3101: Medium severity ibm rational clearcase vulnerability
The login form in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not insert a delay after a failed authentication attempt, which makes it easier for remote attackers to obtain access via a brute-force attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3101?
CVE-2014-3101 has a medium severity rating due to it being susceptible to brute-force attacks.
How do I fix CVE-2014-3101?
To fix CVE-2014-3101, upgrade IBM Rational ClearQuest to version 7.1.2.15 or later, 8.0.0.12 or later, or 8.0.1.5 or later.
Which versions of IBM Rational ClearQuest are affected by CVE-2014-3101?
CVE-2014-3101 affects IBM Rational ClearQuest versions 7.1 prior to 7.1.2.15, 8.0.0 prior to 8.0.0.12, and 8.0.1 prior to 8.0.1.5.
What type of vulnerability is CVE-2014-3101?
CVE-2014-3101 is a security vulnerability in the login form that allows for brute-force attacks due to a lack of delay after failed authentication attempts.
Who is impacted by CVE-2014-3101?
Organizations using affected versions of IBM Rational ClearQuest are at risk of potential unauthorized access due to CVE-2014-3101.