CVE-2014-8925

Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout or insert XSS sequences.
References
Link Resource
http://www-01.ibm.com/support/docview.wss?uid=swg21699148 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:rational_clearquest:7.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.1.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.12:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.14:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.12:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.1.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.1.5:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-03-25 01:59

Updated : 2023-12-10 11:31


NVD link : CVE-2014-8925

Mitre link : CVE-2014-8925

CVE.ORG link : CVE-2014-8925


JSON object : View

Products Affected

ibm

  • rational_clearquest
CWE
CWE-352

Cross-Site Request Forgery (CSRF)