First published: Wed Dec 29 2010(Updated: )
Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dojo Toolkit | ||
IBM Rational ClearQuest | =7.1.1.1 | |
IBM Rational ClearQuest | =7.1.1.2 | |
IBM Rational ClearQuest | =7.1.1.3 | |
IBM Rational ClearQuest | =7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4600 is considered a moderate severity vulnerability due to its potential to expose sensitive cookie information.
To fix CVE-2010-4600, upgrade IBM Rational ClearQuest to version 7.1.1.4 or 7.1.2.1 or later.
Users of IBM Rational ClearQuest versions 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 are affected by CVE-2010-4600.
CVE-2010-4600 can be exploited by remote attackers to read user cookies through the Dojo Toolkit.
CVE-2010-4600 was published in December 2010.