CVE-2008-5328
Last modified
CVE-2008-5328 is a vulnerability of currently unknown severity. The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Rational Clearquest | <= 7.0.0.3 |
| Ibm | Rational Clearquest | 7.0.0.0 |
| Ibm | Rational Clearquest | 7.0.0.1 |
| Ibm | Rational Clearquest | 7.0.0.2 |
| Ibm | Rational Clearquest | 7.0.1 |
| Ibm | Rational Clearquest | 7.0.1.1 |
| Ibm | Rational Clearquest | 7.0.1.2 |
References
- http://secunia.com/advisories/32847Vendor Advisory
- http://secunia.com/advisories/32847Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5328?
How severe is CVE-2008-5328?
How do I fix CVE-2008-5328?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-5322Wysi Wiki Wyg 1.0 allows remote attackers to obtain system i…
- CVE-2008-5323Cross-site scripting (XSS) vulnerability in index.php in Wys…
- CVE-2008-5324Multiple cross-site scripting (XSS) vulnerabilities in CQ We…
- CVE-2008-5325Multiple cross-site scripting (XSS) vulnerabilities in CQ We…
- CVE-2008-5326The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7…
- CVE-2008-5327The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7…
- CVE-2008-5329ClearQuest Web in IBM Rational ClearQuest MultiSite before 7…
- CVE-2008-5330Multiple cross-site scripting (XSS) vulnerabilities in the w…
- CVE-2008-5331Adobe Acrobat 9 uses more efficient encryption than previous…
- CVE-2008-5332Multiple PHP remote file inclusion vulnerabilities in Pie 0.…
- CVE-2008-5333SQL injection vulnerability in members.php in NitroTech 0.0.…
- CVE-2008-5334PHP remote file inclusion vulnerability in includes/common.p…
Are you affected by CVE-2008-5328?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
