The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:20
Type | Values Removed | Values Added |
---|---|---|
References | () http://download4.boulder.ibm.com/sar/CMA/RAA/013m6/0/UpdateLog.txt - | |
References | () http://osvdb.org/69008 - | |
References | () http://secunia.com/advisories/41784 - | |
References | () http://securitytracker.com/id?1024601 - | |
References | () http://www.securityfocus.com/bid/44172 - | |
References | () http://www.vupen.com/english/advisories/2010/2732 - Vendor Advisory | |
References | () http://www.zerodayinitiative.com/advisories/ZDI-10-214/ - |
Information
Published : 2010-10-26 18:00
Updated : 2024-11-21 01:20
NVD link : CVE-2010-4094
Mitre link : CVE-2010-4094
CVE.ORG link : CVE-2010-4094
JSON object : View
Products Affected
ibm
- rational_test_lab_manager
- rational_quality_manager
CWE
CWE-255
Credentials Management Errors