VulnerabilityModified
CVE-2012-5765
The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a SQL error message.
MEDIUM 5.0EPSS 1.35%
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a SQL error message.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/rational clearquest
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM72905Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21620048Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80211
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM72905Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21620048Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80211
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.