Vulnerabilities > IBM > Rational Clearquest > 7.0.1.1

DATE CVE VULNERABILITY TITLE RISK
2008-12-05 CVE-2008-5327 Credentials Management vulnerability in IBM Rational Clearquest
The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree.
network
low complexity
ibm CWE-255
6.5
2008-12-05 CVE-2008-5326 Credentials Management vulnerability in IBM Rational Clearquest
The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks.
4.4
2008-12-05 CVE-2008-5325 Cross-Site Scripting vulnerability in IBM Rational Clearquest
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
4.3
2008-03-20 CVE-2007-4592 Cross-Site Scripting vulnerability in IBM Rational Clearquest
Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.
network
ibm CWE-79
4.3
2008-03-11 CVE-2008-1288 Information Exposure vulnerability in IBM Rational Clearquest 7.0.0.2/7.0.1.1
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.
network
low complexity
ibm CWE-200
5.0
2008-03-11 CVE-2008-1287 Configuration vulnerability in IBM Rational Clearquest 7.0.0.2/7.0.1.1
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
network
low complexity
ibm CWE-16
5.0