PT-2008-6453 · Ibm · Ibm Rational Clearquest Multisite
Published
2008-12-05
·
Updated
2017-08-08
·
CVE-2008-5329
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Rational ClearQuest MultiSite versions prior to 7.1
Description
The issue allows remote servers to direct a client's submissions and changes to an arbitrary database. This is achieved by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in a
jtl.properties file.Recommendations
For versions prior to 7.1, update to version 7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the
jtl.properties file to prevent unauthorized modifications to the JTLRMIREGISTRYSERVERS line.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Rational Clearquest Multisite