CVE-2009-1292: Infoleak
UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1292?
CVE-2009-1292 is classified as a medium severity vulnerability.
How do I fix CVE-2009-1292?
To fix CVE-2009-1292, update IBM Rational ClearCase to version 7.0.0.5, 7.0.1.4, or 7.1.0.1 or later.
What software is affected by CVE-2009-1292?
CVE-2009-1292 affects IBM Rational ClearCase versions 7.0.0.x prior to 7.0.0.5, 7.0.1.x prior to 7.0.1.4, and 7.1.x prior to 7.1.0.1 on Linux and AIX.
Can local users exploit CVE-2009-1292?
Yes, local users can exploit CVE-2009-1292 to obtain sensitive credentials by listing the process.
What type of vulnerability is CVE-2009-1292?
CVE-2009-1292 is a command line exposure vulnerability that leads to the disclosure of credentials.