IBM Rational ClearQuest Information Disclosure Weakness
BID:28132
Info
IBM Rational ClearQuest Information Disclosure Weakness
| Bugtraq ID: | 28132 |
| Class: | Design Error |
| CVE: |
CVE-2008-1287 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM Rational ClearQuest 7.0.1 .1 IBM Rational ClearQuest 7.0 .2 |
| Not Vulnerable: | |
Discussion
IBM Rational ClearQuest Information Disclosure Weakness
IBM Rational ClearQuest is prone to an information-disclosure weakness due to a design error.
Attacker can exploit this issue to enumerate legitimate usernames. This may help in other attacks.
This issue affects ClearQuest 7.0.1.1 and 7.0.0.2; other versions may also be vulnerable.
IBM Rational ClearQuest is prone to an information-disclosure weakness due to a design error.
Attacker can exploit this issue to enumerate legitimate usernames. This may help in other attacks.
This issue affects ClearQuest 7.0.1.1 and 7.0.0.2; other versions may also be vulnerable.
Exploit / POC
IBM Rational ClearQuest Information Disclosure Weakness
An attacker will likely use standard tools or a browser to launch an attack.
An attacker will likely use standard tools or a browser to launch an attack.
Solution / Fix
IBM Rational ClearQuest Information Disclosure Weakness
Solution:
The vendor released an advisory and patches. Please see the references for more information.
Solution:
The vendor released an advisory and patches. Please see the references for more information.
References
IBM Rational ClearQuest Information Disclosure Weakness
References:
References: