CVE-2010-4602
29.12.2010, 18:00
The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | rational_clearquest | 7.1.1.1 |
ibm | rational_clearquest | 7.1.1.2 |
ibm | rational_clearquest | 7.1.1.3 |
ibm | rational_clearquest | 7.1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References