CVE-2009-4357
Summary
| CVE | CVE-2009-4357 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-18 19:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Rational Clearcase | 7.0.0.1 | All | All | All |
| Application | Ibm | Rational Clearcase | 7.0.0.2 | All | All | All |
| Application | Ibm | Rational Clearcase | 7.0.0.4 | All | All | All |
| Application | Ibm | Rational Clearcase | 7.0.1.1 | All | All | All |
| Application | Ibm | Rational Clearcase | 7.0.1.3 | All | All | All |
| Application | Ibm | Rational Clearcase | All | All | All | All |
| Application | Ibm | Rational Clearquest | 2007 | All | All | All |
| Application | Ibm | Rational Clearquest | 2008 | All | All | All |
| Application | Ibm | Rational Clearquest | 5.00 | All | All | All |
| Application | Ibm | Rational Clearquest | 5.20 | All | All | All |
| Application | Ibm | Rational Clearquest | 6.00 | All | All | All |
| Application | Ibm | Rational Clearquest | 6.10 | All | All | All |
| Application | Ibm | Rational Clearquest | 6.12 | All | All | All |
| Application | Ibm | Rational Clearquest | 6.13 | All | All | All |
| Application | Ibm | Rational Clearquest | 6.14 | All | All | All |
| Application | Ibm | Rational Clearquest | 6.15 | All | All | All |
| Application | Ibm | Rational Clearquest | 6.16 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.0 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.0.0.1 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.0.1 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.0.1.0 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.0.1.1 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.0.1.3 | All | All | All |
| Application | Ibm | Rational Clearquest | 7.0.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM PK86377: CQWeb 7.1: password exposed when using legacy URL's to automatic ally log in to CQWeb | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| SecurityTracker.com Archives - IBM Rational ClearQuest Web Interface May Disclose Passwords in Certain Cases | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM Rational ClearQuest CQWeb Interface Password Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM Rational ClearQuest CQWeb Information Disclosure Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.