cbcvebase.

Ibm Rational Clearquest vulnerabilities

42 known vulnerabilities affecting ibm/rational_clearquest.

Total CVEs
42
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM31LOW3

Vulnerabilities

Page 1 of 3
CVE-2012-0708P2CRITICALCVSS 9.3PoCv7.1.1v7.1.1.1+12 more2012-04-22
CVE-2012-0708 [CRITICAL] CWE-119 CVE-2012-0708: Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.
nvd
CVE-2007-4368P3HIGHCVSS 7.5PoCv7.0.0.0v7.0.0.12007-08-15
CVE-2007-4368 [HIGH] CWE-89 CVE-2007-4368: SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.
nvd
CVE-2012-0744P4MEDIUMCVSS 5.0PoCv7.1.1.1v7.1.1.2+17 more2012-08-17
CVE-2012-0744 [MEDIUM] CWE-200 CVE-2012-0744: IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obt IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or
nvd
CVE-2011-1390P3HIGHCVSS 7.5v7.1.1.1v7.1.1.2+14 more2012-05-14
CVE-2011-1390 [HIGH] CWE-89 CVE-2011-1390: SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1. SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.
nvd
CVE-2007-4592P4MEDIUMCVSS 4.3PoC≤ 2003-06-16v7.0.1+2 more2008-03-20
CVE-2007-4592 [MEDIUM] CWE-79 CVE-2007-4592: Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.
nvd
CVE-2008-5330P4MEDIUMCVSS 4.3PoCv7.0.0.0v7.0.0.1+5 more2008-12-05
CVE-2008-5330 [MEDIUM] CWE-79 CVE-2008-5330: Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.
nvd
CVE-2010-4601P3CRITICALCVSS 10.0v7.0v7.0.0.0+25 more2010-12-29
CVE-2010-4601 [CRITICAL] CVE-2010-4601: Multiple unspecified vulnerabilities in IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x befor Multiple unspecified vulnerabilities in IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 allow attackers to have an unknown impact via vectors related to third-party .ocx files.
nvd
CVE-2008-5329P3HIGHCVSS 7.5≤ 7.0.0.3v7.0.0.0+5 more2008-12-05
CVE-2008-5329 [HIGH] CVE-2008-5329: ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a cli ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary database by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in a jtl.properties file.
nvd
CVE-2014-0950P3HIGHCVSS 7.1≥ 7.1.1, ≤ 7.1.1.9≥ 7.1.2, ≤ 7.1.2.13+2 more2018-04-20
CVE-2014-0950 [HIGH] CWE-611 CVE-2014-0950: Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native c Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9, 7.1.2 through 7.1.2.13, 8.0.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of se
nvd
CVE-2007-5090P4HIGHCVSS 7.5v5.00v5.20+9 more2007-09-26
CVE-2007-5090 [HIGH] CWE-264 CVE-2007-5090: Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors.
nvd
CVE-2010-2517P4HIGHCVSS 7.5≤ 7.1.1.1v5.00+33 more2010-06-30
CVE-2010-2517 [HIGH] CVE-2010-2517: Multiple unspecified vulnerabilities in IBM Rational ClearQuest before 7.1.1.02 have unknown impact Multiple unspecified vulnerabilities in IBM Rational ClearQuest before 7.1.1.02 have unknown impact and attack vectors, as demonstrated by an AppScan report.
nvd
CVE-2016-2922P4MEDIUMCVSS 5.9≥ 8.0.0.0, ≤ 8.0.0.21≥ 8.0.1.0, ≤ 8.0.1.17+53 more2018-08-13
CVE-2016-2922 [MEDIUM] CWE-295 CVE-2016-2922: IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) f IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an impersonating server observing all the data transmitted to the real server. IBM X-Force ID: 113353.
nvd
CVE-2010-4603P4MEDIUMCVSS 6.5v7.0v7.0.0.0+25 more2010-12-29
CVE-2010-4603 [MEDIUM] CVE-2010-4603: IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 do IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 does not prevent modification of back-reference fields, which allows remote authenticated users to interfere with intended record relationships, and possibly cause a denial of service (loop) or have unspecified other impact, by (1) adding or (2) removing a back r
nvd
CVE-2013-0598P4MEDIUMCVSS 6.8v7.1.1.1v7.1.1.2+27 more2013-09-28
CVE-2013-0598 [MEDIUM] CWE-352 CVE-2013-0598: Cross-site request forgery (CSRF) vulnerability in the Web Client in IBM Rational ClearQuest 7.1 bef Cross-site request forgery (CSRF) vulnerability in the Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to hijack the authentication of arbitrary users.
nvd
CVE-2008-5327P4MEDIUMCVSS 6.5v7.0v7.0.0.0+7 more2008-12-05
CVE-2008-5327 [MEDIUM] CWE-255 CVE-2008-5327: The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree.
nvd
CVE-2014-8925P4MEDIUMCVSS 6.8v7.1v7.1.0.1+46 more2015-03-25
CVE-2014-8925 [MEDIUM] CWE-352 CVE-2014-8925: Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x b Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout or insert XSS sequences.
nvd
CVE-2024-28796P4MEDIUMCVSS 5.4≥ 9.1, < 9.1.0.72024-07-17
CVE-2024-28796 [MEDIUM] CWE-79 CVE-2024-28796: IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerabi IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286833.
nvd
CVE-2005-2994P4MEDIUMCVSS 6.8v5.00v5.20+6 more2005-09-20
CVE-2005-2994 [MEDIUM] CVE-2005-2994: Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, a Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (XSS).
nvd
CVE-2012-2164P4MEDIUMCVSS 5.5v7.1.1.1v7.1.1.2+16 more2012-08-17
CVE-2012-2164 [MEDIUM] CWE-264 CVE-2012-2164: The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering attack.
nvd
CVE-2011-1205P4MEDIUMCVSS 6.9v7.0.0.4v7.0.0.5+24 more2011-03-29
CVE-2011-1205 [MEDIUM] CWE-119 CVE-2011-1205: Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1. Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a Trojan horse HTML document in the My Computer zone.
nvd
Ibm Rational Clearquest vulnerabilities | cvebase