CVE Vulnerabilities

CVE-2015-5039

Published: Mar 26, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information or modify network traffic via a crafted certificate. IBM X-Force ID: 106715.

Affected Software

NameVendorStart VersionEnd Version
Rational_clearcaseIbm7.1 (including)7.1.2.16 (including)
Rational_clearcaseIbm8.0 (excluding)8.0.0.17 (including)
Rational_clearcaseIbm8.0.1 (including)8.0.1.10 (including)

References