First published: Sat Sep 28 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in the Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to hijack the authentication of arbitrary users.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational ClearQuest | =7.1.1.1 | |
IBM Rational ClearQuest | =7.1.1.2 | |
IBM Rational ClearQuest | =7.1.1.3 | |
IBM Rational ClearQuest | =7.1.1.4 | |
IBM Rational ClearQuest | =7.1.1.5 | |
IBM Rational ClearQuest | =7.1.1.6 | |
IBM Rational ClearQuest | =7.1.1.7 | |
IBM Rational ClearQuest | =7.1.1.8 | |
IBM Rational ClearQuest | =7.1.2 | |
IBM Rational ClearQuest | =7.1.2.1 | |
IBM Rational ClearQuest | =7.1.2.2 | |
IBM Rational ClearQuest | =7.1.2.3 | |
IBM Rational ClearQuest | =7.1.2.4 | |
IBM Rational ClearQuest | =7.1.2.5 | |
IBM Rational ClearQuest | =7.1.2.6 | |
IBM Rational ClearQuest | =7.1.2.7 | |
IBM Rational ClearQuest | =7.1.2.8 | |
IBM Rational ClearQuest | =7.1.2.9 | |
IBM Rational ClearQuest | =7.1.2.10 | |
IBM Rational ClearQuest | =7.1.2.11 | |
IBM Rational ClearQuest | =8.0 | |
IBM Rational ClearQuest | =8.0.0.1 | |
IBM Rational ClearQuest | =8.0.0.2 | |
IBM Rational ClearQuest | =8.0.0.3 | |
IBM Rational ClearQuest | =8.0.0.4 | |
IBM Rational ClearQuest | =8.0.0.5 | |
IBM Rational ClearQuest | =8.0.0.6 | |
IBM Rational ClearQuest | =8.0.0.7 | |
IBM Rational ClearQuest | =8.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0598 is classified as a medium severity vulnerability regarding cross-site request forgery in IBM Rational ClearQuest.
To fix CVE-2013-0598, update IBM Rational ClearQuest to version 7.1.2.12 or later for version 7.1 or to version 8.0.0.8 or later for version 8.0.
CVE-2013-0598 affects IBM Rational ClearQuest versions 7.1 before 7.1.2.12 and 8.0 before 8.0.0.8.
CVE-2013-0598 involves a cross-site request forgery (CSRF) attack, allowing remote attackers to hijack user authentication.
Yes, CVE-2013-0598 can allow unauthorized actions by exploiting CSRF vulnerabilities to impersonate users.