First published: Fri Aug 17 2012(Updated: )
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication is enabled, allows remote authenticated users to read password hashes via a user query.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational ClearQuest | =7.1.1.1 | |
IBM Rational ClearQuest | =7.1.1.2 | |
IBM Rational ClearQuest | =7.1.1.3 | |
IBM Rational ClearQuest | =7.1.1.4 | |
IBM Rational ClearQuest | =7.1.1.5 | |
IBM Rational ClearQuest | =7.1.1.6 | |
IBM Rational ClearQuest | =7.1.1.7 | |
IBM Rational ClearQuest | =7.1.1.8 | |
IBM Rational ClearQuest | =7.1.2 | |
IBM Rational ClearQuest | =7.1.2.1 | |
IBM Rational ClearQuest | =7.1.2.2 | |
IBM Rational ClearQuest | =7.1.2.3 | |
IBM Rational ClearQuest | =7.1.2.4 | |
IBM Rational ClearQuest | =7.1.2.5 | |
IBM Rational ClearQuest | =7.1.2.6 | |
IBM Rational ClearQuest | =8.0.0 | |
IBM Rational ClearQuest | =8.0.0.1 | |
IBM Rational ClearQuest | =8.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2165 has been rated as a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2012-2165, update IBM Rational ClearQuest to version 7.1.2.7 or later for 7.1.x, or version 8.0.0.3 or later for 8.x.
Users of IBM Rational ClearQuest versions 7.1.1.x and 8.0.0.x with authentication enabled are affected by CVE-2012-2165.
CVE-2012-2165 allows remote authenticated users to read password hashes, potentially enabling further exploitation.
Yes, CVE-2012-2165 requires the attacker to be a remote authenticated user to exploit the vulnerability.