VulnerabilityModified
CVE-2008-1287
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
MEDIUM 5.0EPSS 1.44%
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- ibm/rational clearquest
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29280Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK55561Patch
- http://www.securityfocus.com/bid/28132Patch
- http://www.securitytracker.com/id?1019566
- http://www.vupen.com/english/advisories/2008/0804/referencesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41042
- http://secunia.com/advisories/29280Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK55561Patch
- http://www.securityfocus.com/bid/28132Patch
- http://www.securitytracker.com/id?1019566
- http://www.vupen.com/english/advisories/2008/0804/referencesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41042
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.