Rational Software's vulnerability footprint is narrow, centered on legacy development and version-control tools such as ClearCase and related administrative components. The observed disclosure signal reflects application-layer and configuration weaknesses characteristic of enterprise software from this era. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rational Software over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2783HIGH Unspecified vulnerability in Rational Soft Hidden Administrator 1.7 and earlier allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors. | May 21, 2007 | 10.0 | 38 | NO | YES |
CVE-2001-0855HIGH Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable. | Dec 6, 2001 | 7.2 | 27 | NO | YES |
CVE-2002-1322MEDIUM Rational ClearCase 4.1, 2002.05, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain packets to port 371, e.g. via nmap. | Dec 11, 2002 | 5.0 | 25 | NO | YES |
CVE-1999-0350MEDIUM Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits. | Feb 8, 1999 | 6.2 | 25 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rational Software.
Media articles that mention a CVE ID that affects a product developed by Rational Software — matched by CVE ID, not by vendor name.