IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rational_clearquest | Ibm | 7.0.0.2 (including) | 7.0.0.2 (including) |
Rational_clearquest | Ibm | 7.0.1.1 (including) | 7.0.1.1 (including) |