Unrated severityNVD Advisory· Published Aug 15, 2007· Updated Apr 23, 2026
CVE-2007-4368
CVE-2007-4368
Description
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.
Affected products
2cpe:2.3:a:ibm:rational_clearquest:7.0.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:rational_clearquest:7.0.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:rational_clearquest:7.0.0.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7News mentions
0No linked articles in our index yet.