5
CVE-2009-4357
- EPSS 0.34%
- Veröffentlicht 18.12.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Rational Clearcase Version <= 7.1
Ibm ≫ Rational Clearcase Version7.0.0.1
Ibm ≫ Rational Clearcase Version7.0.0.2
Ibm ≫ Rational Clearcase Version7.0.0.4
Ibm ≫ Rational Clearcase Version7.0.1.1
Ibm ≫ Rational Clearcase Version7.0.1.3
Ibm ≫ Rational Clearquest Version5.00
Ibm ≫ Rational Clearquest Version5.20
Ibm ≫ Rational Clearquest Version6.00
Ibm ≫ Rational Clearquest Version6.10
Ibm ≫ Rational Clearquest Version6.12
Ibm ≫ Rational Clearquest Version6.13
Ibm ≫ Rational Clearquest Version6.14
Ibm ≫ Rational Clearquest Version6.15
Ibm ≫ Rational Clearquest Version6.16
Ibm ≫ Rational Clearquest Version7.0
Ibm ≫ Rational Clearquest Version7.0.0.1
Ibm ≫ Rational Clearquest Version7.0.1
Ibm ≫ Rational Clearquest Version7.0.1.0
Ibm ≫ Rational Clearquest Version7.0.1.1
Ibm ≫ Rational Clearquest Version7.0.1.3
Ibm ≫ Rational Clearquest Version7.0.2
Ibm ≫ Rational Clearquest Version2007
Ibm ≫ Rational Clearquest Version2008
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.34% | 0.535 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.