CVE-2010-4602
IBM Rational ClearQuest 7.1.1.x-7.1.1.4 & 7.1.2.x-7.1.2.1 - Authenticated Access Control Bypass
Title source: llmDescription
The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.
References (4)
Core 4
Core References
Various Sources x_refsource_confirm
ftp://public.dhe.ibm.com/software/rational/clearquest/7.1.1/7.1.1.4-RATL-RCQ/7.1.1.4-RATL-RCQ.ux.readme
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/45646
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64440
Exploit vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM20172
Scores
EPSS
0.0115
EPSS Percentile
63.6%
Details
CWE
CWE-264
Status
published
Products (4)
ibm/rational_clearquest
7.1.1.1
ibm/rational_clearquest
7.1.1.2
ibm/rational_clearquest
7.1.1.3
ibm/rational_clearquest
7.1.2
Published
Dec 29, 2010
Tracked Since
Feb 18, 2026