Описание
The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.0.0.3 (включая)
Одно из
cpe:2.3:a:ibm:rational_clearquest:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.1.2:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00533
Низкий
4.6 Medium
CVSS2
Дефекты
CWE-310
Связанные уязвимости
github
больше 3 лет назад
The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.
EPSS
Процентиль: 67%
0.00533
Низкий
4.6 Medium
CVSS2
Дефекты
CWE-310