Rational Clearcase
Vendor:
First CVE: Apr 14, 2009 · Active for 17 years
19
Total CVEs
More Total CVEs than 95% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 23% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rational Clearcase over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2009
17 years ago
Most Recent CVE
Feb 15, 2019
2,719 days ago
CVE Severity & Scoring
Rational Clearcase19 CVEs
11%
58%
21%
11%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (15.8%)
Unknown16 (84.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (10.5%)
High1 (5.3%)
Unknown16 (84.2%)
User Interaction
None3 (15.8%)
Unknown16 (84.2%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (15.8%)
Unknown16 (84.2%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-4059CRITICAL IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and gain unauthorized access to the | Feb 15, 2019 | 9.8 | 30 | NO | NO |
CVE-2014-6221HIGH The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 does not properly generate | Apr 6, 2015 | 9.4 | 30 | NO | NO |
CVE-2014-0931CRITICAL Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java interface, (4) ClearCase remot | Apr 20, 2018 | 9.1 | 25 | NO | NO |
CVE-2011-1205MEDIUM Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through | Mar 29, 2011 | 6.9 | 21 | NO | NO |
CVE-2015-5039HIGH The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.5 | Mar 26, 2018 | 7.4 | 20 | NO | NO |
CVE-2014-3090MEDIUM IBM Rational ClearCase 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted | Sep 23, 2014 | 5.0 | 19 | NO | NO |
CVE-2014-0829MEDIUM Multiple buffer overflows in IBM Rational ClearCase 7.x before 7.1.2.13, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.3 allow remote authenticated users to obtain privileged a | Mar 21, 2014 | 6.5 | 18 | NO | NO |
CVE-2013-5416HIGH Unspecified vulnerability in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unknown vectors. | Dec 18, 2013 | 7.2 | 18 | NO | NO |
CVE-2013-5415HIGH Buffer overflow in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unspecified vectors. | Dec 18, 2013 | 7.2 | 18 | NO | NO |
CVE-2013-5373MEDIUM The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script, which allows local users to ga | Sep 25, 2013 | 6.9 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Rational Clearcase
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0.1.6 | 2 | 5.3 | 1.5% | 0 | 0 |
| 8.0.1.5 | 2 | 5.3 | 1.5% | 0 | 0 |
| 8.0.1.4 | 8 | 5.1 | 1.8% | 0 | 0 |
| 8.0.1.3 | 8 | 5.1 | 1.8% | 0 | 0 |
| 8.0.1.2 | 9 | 5.2 | 1.8% | 0 | 0 |
| 8.0.1.1 | 12 | 5.5 | 1.5% | 0 | 0 |
| 8.0.1 | 13 | 5.6 | 1.4% | 0 | 0 |
| 8.0.0.9 | 9 | 5.2 | 1.8% | 0 | 0 |
| 8.0.0.8 | 12 | 5.5 | 1.5% | 0 | 0 |
| 8.0.0.7 | 13 | 5.6 | 1.4% | 0 | 0 |
| 8.0.0.6 | 13 | 5.6 | 1.4% | 0 | 0 |
| 8.0.0.5 | 13 | 5.6 | 1.4% | 0 | 0 |
| 8.0.0.4 | 13 | 5.6 | 1.4% | 0 | 0 |
| 8.0.0.3 | 13 | 5.6 | 1.4% | 0 | 0 |
| 8.0.0.2 | 12 | 5.5 | 1.5% | 0 | 0 |
| 8.0.0.13 | 2 | 5.3 | 1.5% | 0 | 0 |
| 8.0.0.12 | 2 | 5.3 | 1.5% | 0 | 0 |
| 8.0.0.11 | 8 | 5.1 | 1.8% | 0 | 0 |
| 8.0.0.10 | 8 | 5.1 | 1.8% | 0 | 0 |
| 8.0.0.1 | 12 | 5.5 | 1.5% | 0 | 0 |