CVE-2007-4368: SQL Injection
Published Aug 15, 2007
·Updated
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.
Affected Software
2 affected components
IBM Rational ClearQuest=7.0.0.0
IBM Rational ClearQuest=7.0.0.1
Event History
Aug 15, 2007
CVE Published
11:17 PM
Aug 16, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4368?
CVE-2007-4368 is classified with a high severity due to its potential for remote SQL command execution.
2
How do I fix CVE-2007-4368?
To fix CVE-2007-4368, update IBM Rational ClearQuest to a version that is not affected by this vulnerability.
3
What software versions are affected by CVE-2007-4368?
CVE-2007-4368 affects IBM Rational ClearQuest versions 7.0.0.0-IFIX02 and 7.0.0.1.
4
What type of vulnerability is CVE-2007-4368?
CVE-2007-4368 is a SQL injection vulnerability.
5
Can CVE-2007-4368 allow attackers to access sensitive data?
Yes, CVE-2007-4368 can allow attackers to execute arbitrary SQL commands, potentially exposing sensitive data.