Page 3 of 19 results (0.003 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de secuencias de ejecución de comandos en sitios cruzados en CQ Web en IBM Rational ClearQuest v7.0.0 anterior a la v7.0.0.4 y 7.0.1 anterior a la v7.0.1.3 permitiría a atacantes remotos inyectar secuencias de comandos web o HTML a su elección a través de vectores no específicos. • http://secunia.com/advisories/32847 http://www-01.ibm.com/support/docview.wss?uid=swg1PK69316 http://www.osvdb.org/50369 http://www.securityfocus.com/bid/32576 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 9EXPL: 0

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree. La herramienta ClearQuest Maintenance en IBM Rational ClearQuest v7 anterior a la v7.1 almacena la contraseña de la base de datos en texto claro en un objeto en un perfil de conexión de ClearQuest o un fichero de exportación, que permitiría a usuarios remotos autenticados obtener información sensible localizando el objeto contraseña en el árbol de objetos. • http://secunia.com/advisories/32847 http://www-01.ibm.com/support/docview.wss?uid=swg1PK65908 https://exchange.xforce.ibmcloud.com/vulnerabilities/46995 • CWE-255: Credentials Management Errors •

CVSS: 4.3EPSS: 0%CPEs: 4EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component. Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en la interfaz web para IBM Rational ClearQuest versiones anteriores a 2003.06.16 Parche 2008A, 7.0.0.2_iFix01 y 7.0.1.1_iFix01, permiten a los atacantes remotos inyectar script web o HTML arbitrario por medio de los parámetros (1) contextid , (2) username, (3) userNameVal y (4) schema en el componente login. IBM Rational ClearQuest Web suffers from multiple cross site scripting vulnerabilities. • https://www.exploit-db.com/exploits/31438 http://secunia.com/advisories/29467 http://securityreason.com/securityalert/3753 http://www.securityfocus.com/archive/1/489861/100/0/threaded http://www.securityfocus.com/bid/28296 http://www.securitytracker.com/id?1019685 http://www.vupen.com/english/advisories/2008/0952/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41328 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.0EPSS: 1%CPEs: 2EXPL: 0

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames. IBM Rational ClearQuest versiones 7.0.1.1.1 y 7.0.0.0.2, genera diferentes mensajes de error dependiendo de si el nombre de usuario es válido o no válido, lo que permite a los atacantes remotos enumerar los nombres de usuario. • http://secunia.com/advisories/29280 http://www-1.ibm.com/support/docview.wss?uid=swg1PK55561 http://www.securityfocus.com/bid/28132 http://www.securitytracker.com/id?1019566 http://www.vupen.com/english/advisories/2008/0804/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41042 • CWE-16: Configuration •

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 0

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies. IBM Rational ClearQuest 7.0.1.1 y 7.0.0.2 podrían permitir a atacantes locales o remotos obtener información sensible sobre usuarios mediante la lectura de las cookies de los usuarios. • http://secunia.com/advisories/29280 http://www-1.ibm.com/support/docview.wss?uid=swg1PK55753 http://www.securityfocus.com/bid/28133 http://www.securitytracker.com/id?1019567 http://www.vupen.com/english/advisories/2008/0804/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41043 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •