Ibm Rational Clearquest vulnerabilities
42 known vulnerabilities affecting ibm/rational_clearquest.
Total CVEs
42
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM31LOW3
Vulnerabilities
Page 2 of 3
CVE-2010-4600P4MEDIUMCVSS 5.0v7.1.1.1v7.1.1.2+2 more2010-12-29
CVE-2010-4600 [MEDIUM] CWE-200 CVE-2010-4600: Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.
Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.
nvd
CVE-2010-4602P4MEDIUMCVSS 4.0v7.1.1.1v7.1.1.2+2 more2010-12-29
CVE-2010-4602 [MEDIUM] CWE-264 CVE-2010-4602: The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows r
The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.
nvd
CVE-2009-2212P4MEDIUMCVSS 5.0v7.0.0.0v7.0.0.1+9 more2009-06-25
CVE-2009-2212 [MEDIUM] CVE-2009-2212: The CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows att
The CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows attackers to discover a (1) username or (2) password via unspecified vectors.
nvd
CVE-2015-4996P4MEDIUMCVSS 5.1v7.1v7.1.0.1+50 more2016-01-02
CVE-2015-4996 [MEDIUM] CWE-200 CVE-2015-4996: IBM Rational ClearQuest 7.1.x and 8.0.0.x before 8.0.0.17 and 8.0.1.x before 8.0.1.10 allows local u
IBM Rational ClearQuest 7.1.x and 8.0.0.x before 8.0.0.17 and 8.0.1.x before 8.0.1.10 allows local users to spoof database servers and discover credentials via unspecified vectors.
nvd
CVE-2008-5328P4MEDIUMCVSS 4.6≤ 7.0.0.3v7.0.0.0+5 more2008-12-05
CVE-2008-5328 [MEDIUM] CWE-310 CVE-2008-5328: The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in
The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.
nvd
CVE-2008-1287P4MEDIUMCVSS 5.0v7.0.0.2v7.0.1.12008-03-11
CVE-2008-1287 [MEDIUM] CWE-16 CVE-2008-1287: IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
nvd
CVE-2008-5325P4MEDIUMCVSS 4.3≥ 7.0.0.0, < 7.0.0.4≥ 7.0.1, < 7.0.1.32008-12-05
CVE-2008-5325 [MEDIUM] CWE-79 CVE-2008-5325: Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 befor
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-4839P4MEDIUMCVSS 4.3v7.1.2v7.1.2.1+12 more2012-12-20
CVE-2012-4839 [MEDIUM] CVE-2012-4839: The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9
The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.
nvd
CVE-2012-5757P4MEDIUMCVSS 4.3v7.1.1.1v7.1.1.2+22 more2013-03-21
CVE-2012-5757 [MEDIUM] CWE-79 CVE-2012-5757: Cross-site scripting (XSS) vulnerability in the Web Client in IBM Rational ClearQuest 7.1.x before 7
Cross-site scripting (XSS) vulnerability in the Web Client in IBM Rational ClearQuest 7.1.x before 7.1.2.10 and 8.x before 8.0.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2009-4357P4MEDIUMCVSS 5.0v5.00v5.20+16 more2009-12-18
CVE-2009-4357 [MEDIUM] CWE-200 CVE-2009-4357: CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use o
CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.
nvd
CVE-2009-2211P4MEDIUMCVSS 4.3v7.0v7.0.0.0+12 more2009-06-25
CVE-2009-2211 [MEDIUM] CWE-79 CVE-2009-2211: Cross-site scripting (XSS) vulnerability in the CQWeb server in IBM Rational ClearQuest 7.0.0 before
Cross-site scripting (XSS) vulnerability in the CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-3041P4MEDIUMCVSS 4.3v7.1v7.1.0.1+32 more2013-10-01
CVE-2013-3041 [MEDIUM] CVE-2013-3041: The Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before
The Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to obtain sensitive information from the client-server data stream via unspecified vectors associated with a "JSON hijacking attack."
nvd
CVE-2012-5765P4MEDIUMCVSS 5.0v7.1.2v7.1.2.1+12 more2012-12-20
CVE-2012-5765 [MEDIUM] CWE-200 CVE-2012-5765: The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0
The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a SQL error message.
nvd
CVE-2008-3550P4MEDIUMCVSS 5.0v7.0.12008-08-08
CVE-2008-3550 [MEDIUM] CWE-200 CVE-2008-3550: The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially
The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability.
nvd
CVE-2008-1288P4MEDIUMCVSS 5.0v7.0.0.2v7.0.1.12008-03-11
CVE-2008-1288 [MEDIUM] CWE-200 CVE-2008-1288: IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitiv
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.
nvd
CVE-2007-1468P4MEDIUMCVSS 4.3v7.0.0.02007-03-16
CVE-2007-1468 [MEDIUM] CWE-79 CVE-2007-1468: Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote a
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry.
nvd
CVE-2008-5324P4MEDIUMCVSS 4.3v2007v20082008-12-05
CVE-2008-5324 [MEDIUM] CWE-79 CVE-2008-5324: Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 2007 before
Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 2007 before 2007D and 2008 before 2008B allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-2165P4LOWCVSS 3.5v7.1.1.1v7.1.1.2+16 more2012-08-17
CVE-2012-2165 [LOW] CWE-200 CVE-2012-2165: IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication is enabled, allows remote authenticated users to read password hashes via a user query.
nvd
CVE-2012-2169P4LOWCVSS 3.5v7.1.1.1v7.1.1.2+13 more2012-08-17
CVE-2012-2169 [LOW] CWE-79 CVE-2012-2169: Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM R
Cross-site scripting (XSS) vulnerability in the file-upload functionality in the Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 allows remote authenticated users to inject arbitrary web script or HTML via the File Description field.
nvd
CVE-2008-5326P4MEDIUMCVSS 4.4v7.0.0.0v7.0.0.1+5 more2008-12-05
CVE-2008-5326 [MEDIUM] CWE-255 CVE-2008-5326: The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0
The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks.
nvd