CVE-2012-2164: Medium severity ibm rational clearquest vulnerability
The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2164?
CVE-2012-2164 is considered a medium-severity vulnerability due to the potential for unauthorized access to system settings.
How do I fix CVE-2012-2164?
To fix CVE-2012-2164, update IBM Rational ClearQuest to version 7.1.2.7 or 8.0.0.3 or later.
Who is affected by CVE-2012-2164?
CVE-2012-2164 affects IBM Rational ClearQuest versions 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3.
What kind of attack does CVE-2012-2164 exploit?
CVE-2012-2164 exploits a parameter-tampering attack that allows remote authenticated users to bypass access restrictions.
Can CVE-2012-2164 lead to system configuration changes?
Yes, CVE-2012-2164 can allow unauthorized users to modify system settings through the Site Administration menu.