Vulnerabilities > IBM > Rational Clearquest > 7.0.1.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-12-05 | CVE-2008-5327 | Credentials Management vulnerability in IBM Rational Clearquest The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree. | 6.5 |
2008-12-05 | CVE-2008-5326 | Credentials Management vulnerability in IBM Rational Clearquest The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks. | 4.4 |
2008-12-05 | CVE-2008-5325 | Cross-Site Scripting vulnerability in IBM Rational Clearquest Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 4.3 |
2008-03-20 | CVE-2007-4592 | Cross-Site Scripting vulnerability in IBM Rational Clearquest Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component. | 4.3 |
2008-03-11 | CVE-2008-1288 | Information Exposure vulnerability in IBM Rational Clearquest 7.0.0.2/7.0.1.1 IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies. | 5.0 |
2008-03-11 | CVE-2008-1287 | Configuration vulnerability in IBM Rational Clearquest 7.0.0.2/7.0.1.1 IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames. | 5.0 |