CVE-2010-4600 Information

Description

Dojo Toolkit as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote attackers to read cookies by navigating to a Dojo file related to an \open direct\ issue.

Reference

ftp://public.dhe.ibm.com/software/rational/clearquest/7.1.1/7.1.1.4-RATL-RCQ/7.1.1.4-RATL-RCQ.ux.readme http://secunia.com/advisories/42624 http://www-01.ibm.com/support/docview.wss?uid=swg1PM15146

Share on: