CVE-2009-2212: Medium severity IBM Rational ClearQuest vulnerability
Published Jun 25, 2009
·Updated
The CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows attackers to discover a (1) username or (2) password via unspecified vectors.
Affected Software
11 affected components
IBM Rational ClearQuest=7.0.0.0
IBM Rational ClearQuest=7.0.0.1
IBM Rational ClearQuest=7.0.0.2
IBM Rational ClearQuest=7.0.0.3
IBM Rational ClearQuest=7.0.0.4
IBM Rational ClearQuest=7.0.0.5
IBM Rational ClearQuest=7.0.1
IBM Rational ClearQuest=7.0.1.1
IBM Rational ClearQuest=7.0.1.2
IBM Rational ClearQuest=7.0.1.3
IBM Rational ClearQuest=7.0.1.4
Remediation
Patch Available
Event History
Jun 25, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2212?
CVE-2009-2212 has a medium severity rating as it allows for user credential discovery.
2
How do I fix CVE-2009-2212?
To fix CVE-2009-2212, upgrade IBM Rational ClearQuest to versions 7.0.0.6 or 7.0.1.5 or later.
3
What versions of IBM Rational ClearQuest are affected by CVE-2009-2212?
CVE-2009-2212 affects versions 7.0.0.0 to 7.0.0.5 and 7.0.1.1 to 7.0.1.4.
4
What types of credentials can be exposed in CVE-2009-2212?
CVE-2009-2212 allows attackers to discover both usernames and passwords.
5
Is there a temporary workaround for CVE-2009-2212?
A temporary workaround for CVE-2009-2212 is not specified, so upgrading the software is advisable.