CVE-2014-0950 Information
Feb 14, 2021
cve
Description
Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server (2) ClearQuest Native client (3) ClearQuest Eclipse client and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9 7.1.2 through 7.1.2.13 8.0.0 through 8.0.0.10 and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92623.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21675164 https://exchange.xforce.ibmcloud.com/vulnerabilities/92623
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.1
Share on: