5

CVE-2009-4357

CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
IbmRational Clearcase Version <= 7.1
IbmRational Clearcase Version7.0.0.1
IbmRational Clearcase Version7.0.0.2
IbmRational Clearcase Version7.0.0.4
IbmRational Clearcase Version7.0.1.1
IbmRational Clearcase Version7.0.1.3
IbmRational Clearquest Version5.00
IbmRational Clearquest Version5.20
IbmRational Clearquest Version6.00
IbmRational Clearquest Version6.10
IbmRational Clearquest Version6.12
IbmRational Clearquest Version6.13
IbmRational Clearquest Version6.14
IbmRational Clearquest Version6.15
IbmRational Clearquest Version6.16
IbmRational Clearquest Version7.0
IbmRational Clearquest Version7.0.0.1
IbmRational Clearquest Version7.0.1
IbmRational Clearquest Version7.0.1.0
IbmRational Clearquest Version7.0.1.1
IbmRational Clearquest Version7.0.1.3
IbmRational Clearquest Version7.0.2
IbmRational Clearquest Version2007
IbmRational Clearquest Version2008
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.535
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.