5
CVE-2009-4357
- EPSS 0.34%
- Published 18.12.2009 19:30:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Rational Clearcase Version <= 7.1
Ibm ≫ Rational Clearcase Version7.0.0.1
Ibm ≫ Rational Clearcase Version7.0.0.2
Ibm ≫ Rational Clearcase Version7.0.0.4
Ibm ≫ Rational Clearcase Version7.0.1.1
Ibm ≫ Rational Clearcase Version7.0.1.3
Ibm ≫ Rational Clearquest Version5.00
Ibm ≫ Rational Clearquest Version5.20
Ibm ≫ Rational Clearquest Version6.00
Ibm ≫ Rational Clearquest Version6.10
Ibm ≫ Rational Clearquest Version6.12
Ibm ≫ Rational Clearquest Version6.13
Ibm ≫ Rational Clearquest Version6.14
Ibm ≫ Rational Clearquest Version6.15
Ibm ≫ Rational Clearquest Version6.16
Ibm ≫ Rational Clearquest Version7.0
Ibm ≫ Rational Clearquest Version7.0.0.1
Ibm ≫ Rational Clearquest Version7.0.1
Ibm ≫ Rational Clearquest Version7.0.1.0
Ibm ≫ Rational Clearquest Version7.0.1.1
Ibm ≫ Rational Clearquest Version7.0.1.3
Ibm ≫ Rational Clearquest Version7.0.2
Ibm ≫ Rational Clearquest Version2007
Ibm ≫ Rational Clearquest Version2008
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.34% | 0.535 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.