CVE-2014-3104: Medium severity ibm rational clearcase vulnerability
IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3104?
CVE-2014-3104 is classified as a denial of service vulnerability that can lead to significant disruptions in the IBM Rational ClearQuest service.
How do I fix CVE-2014-3104?
To resolve CVE-2014-3104, users should upgrade to the latest versions of IBM Rational ClearQuest that address the vulnerability.
Which versions are affected by CVE-2014-3104?
CVE-2014-3104 affects IBM Rational ClearQuest versions 7.1 prior to 7.1.2.15 and versions 8.0.0 before 8.0.0.12 and 8.0.1 before 8.0.1.5.
What causes the vulnerability in CVE-2014-3104?
The vulnerability in CVE-2014-3104 arises from the handling of crafted XML documents with a large number of nested entity references.
Can CVE-2014-3104 be exploited remotely?
Yes, CVE-2014-3104 can be exploited by remote attackers to cause denial of service through specially crafted XML documents.