Vulnerability Name: | CVE-2012-2164 (CCN-75039) | ||||||||
Assigned: | 2012-08-08 | ||||||||
Published: | 2012-08-08 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access restrictions, and use the Site Administration menu to modify system settings, via a parameter-tampering attack. | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N) 4.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:H/RL:OF/RC:C)
4.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-2164 Source: AIXAPAR Type: Vendor Advisory PM62735 Source: CCN Type: IBM Security Bulletin 1606318 ClearQuest Web parameter tampering to elevated privileges (CVE-2012-2164) Source: CONFIRM Type: Vendor Advisory http://www.ibm.com/support/docview.wss?uid=swg21606318 Source: XF Type: UNKNOWN rcq-siteadmin-security-bypass(75039) Source: XF Type: UNKNOWN rcq-parameter-tampering(75039) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |