mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
83 lines
2.2 KiB
JSON
83 lines
2.2 KiB
JSON
{
|
|
"CVE_data_meta" : {
|
|
"ASSIGNER" : "cve@mitre.org",
|
|
"ID" : "CVE-2009-4357",
|
|
"STATE" : "PUBLIC"
|
|
},
|
|
"affects" : {
|
|
"vendor" : {
|
|
"vendor_data" : [
|
|
{
|
|
"product" : {
|
|
"product_data" : [
|
|
{
|
|
"product_name" : "n/a",
|
|
"version" : {
|
|
"version_data" : [
|
|
{
|
|
"version_value" : "n/a"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"vendor_name" : "n/a"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"data_format" : "MITRE",
|
|
"data_type" : "CVE",
|
|
"data_version" : "4.0",
|
|
"description" : {
|
|
"description_data" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for automatic login, which might allow attackers to discover the passwords for user accounts via unspecified vectors."
|
|
}
|
|
]
|
|
},
|
|
"problemtype" : {
|
|
"problemtype_data" : [
|
|
{
|
|
"description" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "n/a"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references" : {
|
|
"reference_data" : [
|
|
{
|
|
"name" : "PK86377",
|
|
"refsource" : "AIXAPAR",
|
|
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PK86377"
|
|
},
|
|
{
|
|
"name" : "37385",
|
|
"refsource" : "BID",
|
|
"url" : "http://www.securityfocus.com/bid/37385"
|
|
},
|
|
{
|
|
"name" : "1023370",
|
|
"refsource" : "SECTRACK",
|
|
"url" : "http://securitytracker.com/id?1023370"
|
|
},
|
|
{
|
|
"name" : "37811",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/37811"
|
|
},
|
|
{
|
|
"name" : "ADV-2009-3580",
|
|
"refsource" : "VUPEN",
|
|
"url" : "http://www.vupen.com/english/advisories/2009/3580"
|
|
}
|
|
]
|
|
}
|
|
}
|