VYPR
Unrated severityNVD Advisory· Published May 14, 2012· Updated Apr 29, 2026

CVE-2011-1390

CVE-2011-1390

Description

SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.

Affected products

16
  • cpe:2.3:a:ibm:rational_clearquest:7.1.1.1:*:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:ibm:rational_clearquest:7.1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:7.1.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:rational_clearquest:8.0.0.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.