CVE-2008-5327: Medium severity ibm rational clearquest vulnerability
The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5327?
CVE-2008-5327 is classified as a medium severity vulnerability due to the exposure of sensitive database credentials.
How do I fix CVE-2008-5327?
To fix CVE-2008-5327, update IBM Rational ClearQuest to version 7.1 or later, which resolves the cleartext storage issue.
Who is affected by CVE-2008-5327?
Affected users include those utilizing IBM Rational ClearQuest versions 7.0 and earlier, including various incremental versions.
What type of information is exposed by CVE-2008-5327?
CVE-2008-5327 exposes sensitive database passwords stored in cleartext, which can be accessed by remote authenticated users.
Is there a workaround for CVE-2008-5327?
There is no official workaround for CVE-2008-5327; upgrading to a fixed version is the recommended approach.