CVE-2014-3105: Infoleak
The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of requests.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3105?
CVE-2014-3105 has a medium severity rating due to the potential for account enumeration via failed login messages.
How do I fix CVE-2014-3105?
To fix CVE-2014-3105, update IBM Rational ClearQuest to versions 7.1.2.15 or later, 8.0.0.12 or later, or 8.0.1.5 or later.
What products are affected by CVE-2014-3105?
CVE-2014-3105 affects IBM Rational ClearQuest versions prior to 7.1.2.15, 8.0.0.12, and 8.0.1.5.
What type of vulnerability is CVE-2014-3105?
CVE-2014-3105 is an account enumeration vulnerability that allows remote attackers to identify valid usernames.
Can CVE-2014-3105 impact system security?
Yes, CVE-2014-3105 can compromise system security by allowing attackers to gather valid usernames for potential brute-force attacks.