Description
IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/74831
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/49407
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1026004
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/45871
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/69522
Various Sources vendor-advisory
x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1PM38058
Scores
EPSS
0.0115
EPSS Percentile
63.4%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/rational_build_forge
7.1.2
Published
Sep 08, 2011
Tracked Since
Feb 18, 2026