PT-2012-1518 · Ibm · Ibm Rational Clearquest

Jan Kaestle

·

Publicado

2012-05-14

·

Atualizado

2017-08-17

·

CVE-2011-1390

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Rational ClearQuest versions 7.1.1.x through 7.1.1.8 IBM Rational ClearQuest versions 7.1.2.x through 7.1.2.5 IBM Rational ClearQuest versions 8.x through 8.0.0.1
Description A SQL injection issue exists in the Maintenance tool of IBM Rational ClearQuest, allowing remote attackers to execute arbitrary SQL commands. This is due to an error in the user-database upgrade feature.
Recommendations For IBM Rational ClearQuest versions 7.1.1.x through 7.1.1.8, update to version 7.1.1.9 or later. For IBM Rational ClearQuest versions 7.1.2.x through 7.1.2.5, update to version 7.1.2.6 or later. For IBM Rational ClearQuest versions 8.x through 8.0.0.1, update to version 8.0.0.2 or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1390

Produtos afetados

Ibm Rational Clearquest