CVE-2010-4602

IBM Rational ClearQuest 7.1.1.x-7.1.1.4 & 7.1.2.x-7.1.2.1 - Authenticated Access Control Bypass

Title source: llm
STIX 2.1

Description

The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45646
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64440
Exploit vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM20172

Scores

EPSS 0.0115
EPSS Percentile 63.6%

Details

CWE
CWE-264
Status published
Products (4)
ibm/rational_clearquest 7.1.1.1
ibm/rational_clearquest 7.1.1.2
ibm/rational_clearquest 7.1.1.3
ibm/rational_clearquest 7.1.2
Published Dec 29, 2010
Tracked Since Feb 18, 2026