CVE-2016-2922: Medium severity IBM Rational ClearQuest vulnerability
IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an impersonating server observing all the data transmitted to the real server. IBM X-Force ID: 113353.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2922?
CVE-2016-2922 has a high severity rating due to its potential for man-in-the-middle attacks.
How do I fix CVE-2016-2922?
To mitigate CVE-2016-2922, upgrade IBM Rational ClearQuest to a patched version that checks the SSL certificate against the requested hostname.
What versions of IBM Rational ClearQuest are affected by CVE-2016-2922?
CVE-2016-2922 affects IBM Rational ClearQuest versions 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3.
What type of attack does CVE-2016-2922 enable?
CVE-2016-2922 enables man-in-the-middle attacks where an attacker can intercept data transmitted to a server.
What components of IBM Rational ClearQuest are involved in CVE-2016-2922?
CVE-2016-2922 involves the CQ OSLC linkages and EmailRelay components of IBM Rational ClearQuest.