CVE-2014-8925: XSS
Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout or insert XSS sequences.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What versions of IBM Rational ClearQuest are affected by CVE-2014-8925?
CVE-2014-8925 affects IBM Rational ClearQuest versions 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7.
What is the impact of CVE-2014-8925?
CVE-2014-8925 allows remote attackers to hijack the authentication of arbitrary users, triggering unwanted logouts or potentially inserting XSS sequences.
Is CVE-2014-8925 a critical security vulnerability?
CVE-2014-8925 is classified as a moderately critical cross-site request forgery (CSRF) vulnerability.
How can I mitigate CVE-2014-8925?
To mitigate CVE-2014-8925, upgrade IBM Rational ClearQuest to the patched versions: 7.1.2.17 or newer, 8.0.0.14 or newer, and 8.0.1.7 or newer.
What is the nature of the vulnerability described in CVE-2014-8925?
CVE-2014-8925 is a cross-site request forgery (CSRF) vulnerability that compromises user authentication.