VulnerabilityModified
CVE-2012-2164
The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering…
MEDIUM 5.5EPSS 1.11%
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering attack.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/rational clearquest
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM62735Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21606318Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75039
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM62735Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21606318Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75039
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.