CVE-2014-3103: Infoleak
The Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3103?
CVE-2014-3103 is considered a medium severity vulnerability due to the risk of session cookie interception.
How do I fix CVE-2014-3103?
To fix CVE-2014-3103, upgrade to IBM Rational ClearQuest versions 7.1.2.15, 8.0.0.12, or 8.0.1.5 or later.
What products are affected by CVE-2014-3103?
CVE-2014-3103 affects IBM Rational ClearQuest versions prior to 7.1.2.15, 8.0.0.12, and 8.0.1.5.
What type of attack is possible with CVE-2014-3103?
CVE-2014-3103 allows remote attackers to potentially capture session cookies through man-in-the-middle attacks.
Is there a workaround for CVE-2014-3103?
While there is no specific workaround, enabling secure transmission and configuring secure cookie settings may mitigate risks.