CVE-2012-0708
Summary
| CVE | CVE-2012-0708 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-04-22 18:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Rational Clearquest | 7.1.1 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.1.1 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.1.2 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.1.3 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.1.4 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.2 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.2.1 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.2.2 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.2.3 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.2.4 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.2.5 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.1.2.6 | All | All | All |
| Application | Ibm | Rational Clearquest | 8.0.0 | All | All | All |
| Application | Ibm | Rational Clearquest | 8.0.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM Rational ClearQuest 'cqole.dll' ActiveX Control Heap Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/81443 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Security Bulletin: Rational ClearQuest CQOle ActiveX Control Remote Execution Vulnerability (CVE-2012-0708) | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| IBM Rational ClearQuest Buffer Overflow in ActiveX Control RegisterSchemaRepoFromFileByDbSet() Function Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.