IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to obtain sensitive stack-trace information from CM server error messages via an invalid parameter.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg21606319 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PM61822 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/75048 | vdb entry |