CVE-2014-0950XML External Entity (XXE) Injection in IBM Rational Clearquest

Severity
7.1HIGHNVD
EPSS
0.5%
top 36.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 20
Latest updateMay 14

Description

Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9, 7.1.2 through 7.1.2.13, 8.0.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92623.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:HExploitability: 2.8 | Impact: 4.2

Affected Packages1 packages

NVDibm/rational_clearquest7.1.17.1.1.9+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cvv6-8h36-ppcg: Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) Clea2022-05-14
CVEList
CVE-2014-0950: Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) Clea2018-04-20
CVE-2014-0950 — XML External Entity (XXE) Injection | cvebase