First published: Wed Dec 29 2010(Updated: )
The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational ClearQuest | =7.1.2 | |
IBM Rational ClearQuest | =7.1.1.1 | |
IBM Rational ClearQuest | =7.1.1.3 | |
IBM Rational ClearQuest | =7.1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4602 is considered a medium severity vulnerability due to its potential for unauthorized access to sensitive information.
To fix CVE-2010-4602, upgrade IBM Rational ClearQuest to version 7.1.1.4 or later for 7.1.1.x, and to 7.1.2.1 or later for 7.1.2.x.
CVE-2010-4602 affects users of IBM Rational ClearQuest versions 7.1.1.1 through 7.1.1.3 and 7.1.2.0.
Attackers can exploit CVE-2010-4602 to bypass restricted user limitations and read unauthorized records.
CVE-2010-4602 was disclosed in 2010, highlighting vulnerabilities in specific versions of IBM Rational ClearQuest.