CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2009-12-18T19:00:00Z

Updated: 2024-09-17T03:59:45.984Z

Reserved: 2009-12-18T00:00:00Z

Link: CVE-2009-4357

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2009-12-18T19:30:00.593

Modified: 2009-12-21T05:00:00.000

Link: CVE-2009-4357

cve-icon Redhat

No data.