CVE-2010-4602
published 2010-12-29CVE-2010-4602: The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user"…
PriorityP420medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.15%
63.3th percentile
The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
| ibm | rational_clearquest | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
ftp://public.dhe.ibm.com/software/rational/clearquest/7.1.1/7.1.1.4-RATL-RCQ/7.1.1.4-RATL-RCQ.ux.readmehttp://www-01.ibm.com/support/docview.wss?uid=swg1PM20172http://www.securityfocus.com/bid/45646https://exchange.xforce.ibmcloud.com/vulnerabilities/64440ftp://public.dhe.ibm.com/software/rational/clearquest/7.1.1/7.1.1.4-RATL-RCQ/7.1.1.4-RATL-RCQ.ux.readmehttp://www-01.ibm.com/support/docview.wss?uid=swg1PM20172http://www.securityfocus.com/bid/45646https://exchange.xforce.ibmcloud.com/vulnerabilities/64440
2010-12-29
Published