The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass restricted user limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rational_clearquest | Ibm | 7.1.1.1 (including) | 7.1.1.1 (including) |
Rational_clearquest | Ibm | 7.1.1.2 (including) | 7.1.1.2 (including) |
Rational_clearquest | Ibm | 7.1.1.3 (including) | 7.1.1.3 (including) |
Rational_clearquest | Ibm | 7.1.2 (including) | 7.1.2 (including) |