CVE-2009-4357
18.12.2009, 19:30
CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | rational_clearcase | 𝑥 ≤ 7.1 |
ibm | rational_clearcase | 7.0.0.1 |
ibm | rational_clearcase | 7.0.0.2 |
ibm | rational_clearcase | 7.0.0.4 |
ibm | rational_clearcase | 7.0.1.1 |
ibm | rational_clearcase | 7.0.1.3 |
ibm | rational_clearquest | 5.00 |
ibm | rational_clearquest | 5.20 |
ibm | rational_clearquest | 6.00 |
ibm | rational_clearquest | 6.10 |
ibm | rational_clearquest | 6.12 |
ibm | rational_clearquest | 6.13 |
ibm | rational_clearquest | 6.14 |
ibm | rational_clearquest | 6.15 |
ibm | rational_clearquest | 6.16 |
ibm | rational_clearquest | 7.0 |
ibm | rational_clearquest | 7.0.0.1 |
ibm | rational_clearquest | 7.0.1 |
ibm | rational_clearquest | 7.0.1.0 |
ibm | rational_clearquest | 7.0.1.1 |
ibm | rational_clearquest | 7.0.1.3 |
ibm | rational_clearquest | 7.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References