Lucene search

K
kasperskyKaspersky LabKLA10497
HistoryMar 24, 2015 - 12:00 a.m.

KLA10497 Security bypass vulnerability in IBM Rational ClearQuest

2015-03-2400:00:00
Kaspersky Lab
threats.kaspersky.com
24

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

62.1%

Cross site reference forgery was found in IBM Rational ClearQuest. By exploiting this vulnerability malicious users can bypass security restrictions. This vulnerability can be exploited remotely via a auth hijack.

Original advisories

Related products

IBM-Rational-ClearQuest

CVE list

CVE-2014-8925 high

Solution

Update to latest version!

Impacts

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

Affected Products

  • IBM Rational ClearQuest 7.1 versions earlier than 7.1.2.17IBM Rational ClearQuest 8.0 versions earlier than 8.0.0.14IBM Rational ClearQuest 8.0.1. versions earlier than 8.0.1.7

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

62.1%

Related for KLA10497