Lucene search

K
nvd[email protected]NVD:CVE-2014-3105
HistorySep 23, 2014 - 9:55 p.m.

CVE-2014-3105

2014-09-2321:55:04
CWE-200
web.nvd.nist.gov

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.9%

The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of requests.

Affected configurations

NVD
Node
ibmrational_clearcaseMatch7.1
OR
ibmrational_clearcaseMatch7.1.0.1
OR
ibmrational_clearcaseMatch7.1.0.2
OR
ibmrational_clearcaseMatch7.1.1
OR
ibmrational_clearcaseMatch7.1.1.1
OR
ibmrational_clearcaseMatch7.1.1.2
OR
ibmrational_clearcaseMatch7.1.1.3
OR
ibmrational_clearcaseMatch7.1.1.4
OR
ibmrational_clearcaseMatch7.1.1.5
OR
ibmrational_clearcaseMatch7.1.1.6
OR
ibmrational_clearcaseMatch7.1.1.7
OR
ibmrational_clearcaseMatch7.1.1.8
OR
ibmrational_clearcaseMatch7.1.1.9
OR
ibmrational_clearcaseMatch7.1.2
OR
ibmrational_clearcaseMatch7.1.2.1
OR
ibmrational_clearcaseMatch7.1.2.2
OR
ibmrational_clearcaseMatch7.1.2.3
OR
ibmrational_clearcaseMatch7.1.2.4
OR
ibmrational_clearcaseMatch7.1.2.5
OR
ibmrational_clearcaseMatch7.1.2.6
OR
ibmrational_clearcaseMatch7.1.2.7
OR
ibmrational_clearcaseMatch7.1.2.9
OR
ibmrational_clearcaseMatch7.1.2.10
OR
ibmrational_clearcaseMatch7.1.2.11
OR
ibmrational_clearcaseMatch7.1.2.12
OR
ibmrational_clearcaseMatch7.1.2.13
OR
ibmrational_clearcaseMatch7.1.2.14
OR
ibmrational_clearcaseMatch8.0
OR
ibmrational_clearcaseMatch8.0.0.1
OR
ibmrational_clearcaseMatch8.0.0.2
OR
ibmrational_clearcaseMatch8.0.0.3
OR
ibmrational_clearcaseMatch8.0.0.4
OR
ibmrational_clearcaseMatch8.0.0.5
OR
ibmrational_clearcaseMatch8.0.0.6
OR
ibmrational_clearcaseMatch8.0.0.7
OR
ibmrational_clearcaseMatch8.0.0.8
OR
ibmrational_clearcaseMatch8.0.0.9
OR
ibmrational_clearcaseMatch8.0.0.10
OR
ibmrational_clearcaseMatch8.0.0.11
OR
ibmrational_clearcaseMatch8.0.1
OR
ibmrational_clearcaseMatch8.0.1.1
OR
ibmrational_clearcaseMatch8.0.1.2
OR
ibmrational_clearcaseMatch8.0.1.3
OR
ibmrational_clearcaseMatch8.0.1.4

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.9%

Related for NVD:CVE-2014-3105