PT-2008-6453 · Ibm · Ibm Rational Clearquest Multisite

Published

2008-12-05

·

Updated

2017-08-08

·

CVE-2008-5329

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Rational ClearQuest MultiSite versions prior to 7.1
Description The issue allows remote servers to direct a client's submissions and changes to an arbitrary database. This is achieved by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in a jtl.properties file.
Recommendations For versions prior to 7.1, update to version 7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the jtl.properties file to prevent unauthorized modifications to the JTLRMIREGISTRYSERVERS line.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-5329

Affected Products

Ibm Rational Clearquest Multisite