CVE-2008-5326
- EPSS 0.07%
- Veröffentlicht 05.12.2008 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series o...
CVE-2008-5328
- EPSS 0.53%
- Veröffentlicht 05.12.2008 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by l...
CVE-2008-5329
- EPSS 0.4%
- Veröffentlicht 05.12.2008 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary database by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in ...
CVE-2008-5330
- EPSS 2.25%
- Veröffentlicht 05.12.2008 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to i...
- EPSS 0.26%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scrip...
CVE-2007-4592
- EPSS 16.23%
- Veröffentlicht 20.03.2008 00:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid...
- EPSS 0.46%
- Veröffentlicht 11.03.2008 17:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.
- EPSS 0.5%
- Veröffentlicht 11.03.2008 17:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
CVE-2007-5090
- EPSS 0.9%
- Veröffentlicht 26.09.2007 20:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors.
CVE-2007-4368
- EPSS 6.07%
- Veröffentlicht 15.08.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.