CVE-2008-5328: Medium severity ibm rational clearquest vulnerability
The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5328?
CVE-2008-5328 is classified as a moderate severity vulnerability due to its exposure of sensitive data.
How do I fix CVE-2008-5328?
To mitigate CVE-2008-5328, upgrade to a version of IBM Rational ClearQuest that no longer stores database passwords in cleartext.
What software versions are affected by CVE-2008-5328?
CVE-2008-5328 affects IBM Rational ClearQuest versions up to 7.0.1.2.
What type of information is compromised by CVE-2008-5328?
CVE-2008-5328 compromises sensitive database passwords stored in cleartext.
Who can exploit CVE-2008-5328?
CVE-2008-5328 can be exploited by remote authenticated users with access to the ClearQuest connection profile or export file.