- EPSS 0.89%
- Published 23.09.2014 20:55:02
- Last modified 12.04.2025 10:46:40
IBM Rational ClearCase 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a ...
CVE-2014-0829
- EPSS 0.52%
- Published 21.03.2014 10:55:05
- Last modified 12.04.2025 10:46:40
Multiple buffer overflows in IBM Rational ClearCase 7.x before 7.1.2.13, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.3 allow remote authenticated users to obtain privileged access via unspecified vectors.
CVE-2013-5422
- EPSS 0.23%
- Published 19.12.2013 22:55:04
- Last modified 11.04.2025 00:51:21
The Web Client in IBM Rational ClearQuest 7.1 through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2, when a multi-database dataset exists, allows remote attackers to read database names via unspecified vectors.
CVE-2013-5416
- EPSS 0.05%
- Published 18.12.2013 16:04:33
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unknown vectors.
CVE-2013-5415
- EPSS 0.05%
- Published 18.12.2013 16:04:33
- Last modified 11.04.2025 00:51:21
Buffer overflow in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unspecified vectors.
CVE-2013-5373
- EPSS 0.04%
- Published 25.09.2013 10:31:29
- Last modified 11.04.2025 00:51:21
The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script, which allows local users to gain privileges by appending commands.
CVE-2011-1205
- EPSS 0.05%
- Published 29.03.2011 18:55:02
- Last modified 11.04.2025 00:51:21
Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a...
- EPSS 0.34%
- Published 18.12.2009 19:30:00
- Last modified 09.04.2025 00:30:58
CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.
CVE-2009-1292
- EPSS 0.05%
- Published 14.04.2009 16:26:56
- Last modified 09.04.2025 00:30:58
UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.