OSLC Integration Feature Vulnerability in IBM Rational ClearQuest
CVE-2014-3105
Currently unrated
What is CVE-2014-3105?
The OSLC integration feature in IBM Rational ClearQuest prior to specified versions exposes a critical vulnerability whereby attackers can exploit differing error messages for failed login attempts. This allows unauthorized remote access to enumerate valid account names, potentially leading to further attacks. Organizations using affected versions should implement immediate security measures to mitigate this risk.