CVE-2012-0744
published 2012-08-17CVE-2012-0744: IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a…
PriorityP433medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
8.26%
94.2th percentile
IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or (12) cqweb/j_security_check sample script.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat1.9LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j3rr-79qq-g9pm: IBM Rational ClearQuest 7
ghsa_unreviewed·2022-05-17
CVE-2012-0744 [MEDIUM] CWE-200 GHSA-j3rr-79qq-g9pm: IBM Rational ClearQuest 7
IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or (12) cqweb/j_security_check sample script.
Red Hat
Kernel: xfrm_user: info leak in copy_to_user_auth
vendor_redhat·2012-09-19·CVSS 1.9
CVE-2012-6538 [LOW] Kernel: xfrm_user: info leak in copy_to_user_auth
Kernel: xfrm_user: info leak in copy_to_user_auth
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
This issue affects the versions of Linux kernel as shipped with Red Hat
Enterprise Linux 6 . This issue has been addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2013-0744.html.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affe
No detection rules found.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1PM66896http://www.ibm.com/support/docview.wss?uid=swg21599361http://www.ibm.com/support/docview.wss?uid=swg21606317https://exchange.xforce.ibmcloud.com/vulnerabilities/74671http://www-01.ibm.com/support/docview.wss?uid=swg1PM66896http://www.ibm.com/support/docview.wss?uid=swg21599361http://www.ibm.com/support/docview.wss?uid=swg21606317https://exchange.xforce.ibmcloud.com/vulnerabilities/74671
2012-08-17
Published