VulnerabilityModified
CVE-2009-4357
CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.
MEDIUM 5.0EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/rational clearcase · ibm/rational clearquest
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/37811Vendor Advisory
- http://securitytracker.com/id?1023370
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK86377Vendor Advisory
- http://www.securityfocus.com/bid/37385
- http://www.vupen.com/english/advisories/2009/3580Vendor Advisory
- http://secunia.com/advisories/37811Vendor Advisory
- http://securitytracker.com/id?1023370
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK86377Vendor Advisory
- http://www.securityfocus.com/bid/37385
- http://www.vupen.com/english/advisories/2009/3580Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.