5
CVSSv2

CVE-2012-0744

Published: 17/08/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

IBM Rational ClearQuest 7.1.x up to and including 7.1.2.7 and 8.x up to and including 8.0.0.3 allows remote malicious users to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or (12) cqweb/j_security_check sample script.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm rational clearquest 7.1.2

ibm rational clearquest 7.1.1.3

ibm rational clearquest 7.1.2.1

ibm rational clearquest 7.1.2.5

ibm rational clearquest 7.1.2.6

ibm rational clearquest 7.1.2.3

ibm rational clearquest 7.1.2.2

ibm rational clearquest 7.1.1.4

ibm rational clearquest 7.1.2.4

ibm rational clearquest 7.1.1.6

ibm rational clearquest 7.1.1.8

ibm rational clearquest 7.1.1.2

ibm rational clearquest 7.1.1.1

ibm rational clearquest 7.1.1.5

ibm rational clearquest 7.1.1.7

ibm rational clearquest 8.0

ibm rational clearquest 8.0.0.2

ibm rational clearquest 8.0.0.1

ibm rational clearquest 8.0.0.3

Exploits

source: wwwsecurityfocuscom/bid/55125/info IBM Rational ClearQuest is prone to the following security vulnerabilities: 1 An HTML-injection vulnerability 2 Multiple information-disclosure vulnerabilities 3 A security-bypass vulnerability Attackers may leverage these issues to obtain potentially sensitive session information, bypa ...