The Web client in IBM Rational ClearQuest 7.1.x prior to 7.1.2.7 and 8.x prior to 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm rational clearquest 7.1.2.3 |
||
ibm rational clearquest 7.1.2.2 |
||
ibm rational clearquest 7.1.2.6 |
||
ibm rational clearquest 7.1.1.4 |
||
ibm rational clearquest 7.1.2.4 |
||
ibm rational clearquest 7.1.1.6 |
||
ibm rational clearquest 7.1.1.8 |
||
ibm rational clearquest 7.1.1.2 |
||
ibm rational clearquest 7.1.1.1 |
||
ibm rational clearquest 7.1.1.5 |
||
ibm rational clearquest 7.1.1.7 |
||
ibm rational clearquest 7.1.2 |
||
ibm rational clearquest 7.1.1.3 |
||
ibm rational clearquest 7.1.2.1 |
||
ibm rational clearquest 7.1.2.5 |
||
ibm rational clearquest 8.0 |
||
ibm rational clearquest 8.0.0.1 |
||
ibm rational clearquest 8.0.0.2 |