CVE-2014-3105

The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ibmrational_clearcase
7.1
ibmrational_clearcase
7.1.0.1
ibmrational_clearcase
7.1.0.2
ibmrational_clearcase
7.1.1
ibmrational_clearcase
7.1.1.1
ibmrational_clearcase
7.1.1.2
ibmrational_clearcase
7.1.1.3
ibmrational_clearcase
7.1.1.4
ibmrational_clearcase
7.1.1.5
ibmrational_clearcase
7.1.1.6
ibmrational_clearcase
7.1.1.7
ibmrational_clearcase
7.1.1.8
ibmrational_clearcase
7.1.1.9
ibmrational_clearcase
7.1.2
ibmrational_clearcase
7.1.2.1
ibmrational_clearcase
7.1.2.2
ibmrational_clearcase
7.1.2.3
ibmrational_clearcase
7.1.2.4
ibmrational_clearcase
7.1.2.5
ibmrational_clearcase
7.1.2.6
ibmrational_clearcase
7.1.2.7
ibmrational_clearcase
7.1.2.9
ibmrational_clearcase
7.1.2.10
ibmrational_clearcase
7.1.2.11
ibmrational_clearcase
7.1.2.12
ibmrational_clearcase
7.1.2.13
ibmrational_clearcase
7.1.2.14
ibmrational_clearcase
8.0
ibmrational_clearcase
8.0.0.1
ibmrational_clearcase
8.0.0.2
ibmrational_clearcase
8.0.0.3
ibmrational_clearcase
8.0.0.4
ibmrational_clearcase
8.0.0.5
ibmrational_clearcase
8.0.0.6
ibmrational_clearcase
8.0.0.7
ibmrational_clearcase
8.0.0.8
ibmrational_clearcase
8.0.0.9
ibmrational_clearcase
8.0.0.10
ibmrational_clearcase
8.0.0.11
ibmrational_clearcase
8.0.1
ibmrational_clearcase
8.0.1.1
ibmrational_clearcase
8.0.1.2
ibmrational_clearcase
8.0.1.3
ibmrational_clearcase
8.0.1.4
𝑥
= Vulnerable software versions