Denial of Service Vulnerability in IBM Rational ClearQuest
CVE-2014-3104

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
23 September 2014

Summary

IBM Rational ClearQuest versions prior to 7.1.2.15, 8.0.0.12, and 8.0.1.5 are susceptible to a denial of service attack. This vulnerability enables remote attackers to deplete system memory by sending a specially crafted XML document that contains numerous nested entity references. Such attacks can lead to significant system disruptions and affect overall service availability, reminiscent of the issues outlined in previous CVEs.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.