CVE-2009-4357

CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:rational_clearcase:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearcase:7.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearcase:7.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearcase:7.0.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearcase:7.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearcase:7.0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:5.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:5.20:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:6.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:6.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:6.12:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:6.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:6.14:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:6.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:6.16:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:2007:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:2008:*:*:*:*:*:*:*

History

21 Nov 2024, 01:09

Type Values Removed Values Added
References () http://secunia.com/advisories/37811 - Vendor Advisory () http://secunia.com/advisories/37811 - Vendor Advisory
References () http://securitytracker.com/id?1023370 - () http://securitytracker.com/id?1023370 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg1PK86377 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg1PK86377 - Vendor Advisory
References () http://www.securityfocus.com/bid/37385 - () http://www.securityfocus.com/bid/37385 -
References () http://www.vupen.com/english/advisories/2009/3580 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/3580 - Vendor Advisory

Information

Published : 2009-12-18 19:30

Updated : 2024-11-21 01:09


NVD link : CVE-2009-4357

Mitre link : CVE-2009-4357

CVE.ORG link : CVE-2009-4357


JSON object : View

Products Affected

ibm

  • rational_clearquest
  • rational_clearcase
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor