Remote Database Name Exposure in IBM Rational ClearQuest
CVE-2013-5422

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
19 December 2013

Summary

The Web Client in IBM Rational ClearQuest versions 7.1 through 7.1.2.12, 8.0.0.x prior to 8.0.0.9, and 8.0.1.x before 8.0.1.2 is prone to a vulnerability that enables remote attackers to access database names under certain conditions. This occurs when a multi-database dataset is present, allowing unauthorized information disclosure through unspecified mechanisms. Organizations using these affected versions should consider applying the necessary updates to mitigate potential risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.