CVE-2010-4094

The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:rational_quality_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_test_lab_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:20

Type Values Removed Values Added
References () http://download4.boulder.ibm.com/sar/CMA/RAA/013m6/0/UpdateLog.txt - () http://download4.boulder.ibm.com/sar/CMA/RAA/013m6/0/UpdateLog.txt -
References () http://osvdb.org/69008 - () http://osvdb.org/69008 -
References () http://secunia.com/advisories/41784 - () http://secunia.com/advisories/41784 -
References () http://securitytracker.com/id?1024601 - () http://securitytracker.com/id?1024601 -
References () http://www.securityfocus.com/bid/44172 - () http://www.securityfocus.com/bid/44172 -
References () http://www.vupen.com/english/advisories/2010/2732 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/2732 - Vendor Advisory
References () http://www.zerodayinitiative.com/advisories/ZDI-10-214/ - () http://www.zerodayinitiative.com/advisories/ZDI-10-214/ -

Information

Published : 2010-10-26 18:00

Updated : 2024-11-21 01:20


NVD link : CVE-2010-4094

Mitre link : CVE-2010-4094

CVE.ORG link : CVE-2010-4094


JSON object : View

Products Affected

ibm

  • rational_test_lab_manager
  • rational_quality_manager
CWE
CWE-255

Credentials Management Errors