IBM Rational ClearQuest User Identifier Information Disclosure Weakness
BID:28133
Info
IBM Rational ClearQuest User Identifier Information Disclosure Weakness
| Bugtraq ID: | 28133 |
| Class: | Design Error |
| CVE: |
CVE-2008-1288 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM Rational ClearQuest 7.0.1 .1 IBM Rational ClearQuest 7.0 .2 |
| Not Vulnerable: | |
Discussion
IBM Rational ClearQuest User Identifier Information Disclosure Weakness
IBM Rational ClearQuest is prone to an information-disclosure weakness due to a design error.
Attacker can exploit this issue to gain access to the user identifier, potentially obtaining sensitive information. This may help in other attacks.
This issue affects ClearQuest 7.0.1.1 and 7.0.0.2; other versions may also be vulnerable.
IBM Rational ClearQuest is prone to an information-disclosure weakness due to a design error.
Attacker can exploit this issue to gain access to the user identifier, potentially obtaining sensitive information. This may help in other attacks.
This issue affects ClearQuest 7.0.1.1 and 7.0.0.2; other versions may also be vulnerable.
Exploit / POC
IBM Rational ClearQuest User Identifier Information Disclosure Weakness
An attacker will likely use standard tools to exploit this issue.
An attacker will likely use standard tools to exploit this issue.
Solution / Fix
IBM Rational ClearQuest User Identifier Information Disclosure Weakness
Solution:
The vendor released an advisory and patches to address this issue. Please see the references for more information.
Solution:
The vendor released an advisory and patches to address this issue. Please see the references for more information.
References
IBM Rational ClearQuest User Identifier Information Disclosure Weakness
References:
References: