Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxrr-7663-gg4f

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.

CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.

EPSS

Процентиль: 56%
0.00337
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
около 16 лет назад

CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.

EPSS

Процентиль: 56%
0.00337
Низкий

Дефекты

CWE-200