The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www-1.ibm.com/support/docview.wss?uid=swg1PK68332 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44254 | vdb entry |
http://www.securitytracker.com/id?1020642 | vdb entry |
http://www.vupen.com/english/advisories/2008/2317 | vdb entry |