CVE-2012-2205
- EPSS 0.19%
- Veröffentlicht 17.08.2012 20:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a workspace query.
CVE-2012-2169
- EPSS 0.19%
- Veröffentlicht 17.08.2012 20:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.
- EPSS 0.18%
- Veröffentlicht 17.08.2012 20:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to obtain sensitive stack-trace information from CM server error messages via an invalid parameter.
CVE-2012-2165
- EPSS 0.15%
- Veröffentlicht 17.08.2012 20:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication is enabled, allows remote authenticated users to read password hashes via a user query.
CVE-2012-2164
- EPSS 0.15%
- Veröffentlicht 17.08.2012 20:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering ...
- EPSS 5.96%
- Veröffentlicht 17.08.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) H...
CVE-2011-1390
- EPSS 0.66%
- Veröffentlicht 14.05.2012 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-databas...
CVE-2012-0708
- EPSS 66.57%
- Veröffentlicht 22.04.2012 18:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web pa...
CVE-2011-1205
- EPSS 0.05%
- Veröffentlicht 29.03.2011 18:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a...
- EPSS 0.18%
- Veröffentlicht 29.12.2010 18:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD ac...