First published: Tue Apr 14 2009(Updated: )
UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational ClearCase | =7.0 | |
IBM Rational ClearCase | =7.0.0.1 | |
IBM Rational ClearCase | =7.0.0.2 | |
IBM Rational ClearCase | =7.0.0.3 | |
IBM Rational ClearCase | =7.0.0.4 | |
IBM Rational ClearCase | =7.0.1 | |
IBM Rational ClearCase | =7.0.1.1 | |
IBM Rational ClearCase | =7.0.1.2 | |
IBM Rational ClearCase | =7.0.1.3 | |
IBM Rational ClearCase | =7.1 | |
IBM AIX | ||
Unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1292 is classified as a medium severity vulnerability.
To fix CVE-2009-1292, update IBM Rational ClearCase to version 7.0.0.5, 7.0.1.4, or 7.1.0.1 or later.
CVE-2009-1292 affects IBM Rational ClearCase versions 7.0.0.x prior to 7.0.0.5, 7.0.1.x prior to 7.0.1.4, and 7.1.x prior to 7.1.0.1 on Linux and AIX.
Yes, local users can exploit CVE-2009-1292 to obtain sensitive credentials by listing the process.
CVE-2009-1292 is a command line exposure vulnerability that leads to the disclosure of credentials.