The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/46994 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1PK30938 | patch vendor advisory |
http://secunia.com/advisories/32847 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/32577 | vdb entry |