Denial of Service Flaw in IBM Rational ClearCase Software
CVE-2014-3090

Currently unrated

Key Information:

Vendor

IBM

Vendor
CVE Published:
23 September 2014

What is CVE-2014-3090?

A vulnerability in IBM Rational ClearCase allows remote attackers to perform denial of service attacks by leveraging specially crafted XML documents filled with extensive nested entity references. This fault leads to excessive memory consumption, potentially crippling the application and disrupting services. Users of affected versions 7.1, 8.0.0, and 8.0.1 should consider upgrading to the latest patches to mitigate the risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.