PT-2011-1253 · Ibm · Ibm Rational Asset Manager

Published

2011-11-05

·

Updated

2022-10-28

·

CVE-2011-4820

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Rational Asset Manager versions 7.5
Description The issue is related to insufficient access control in the processing of the UID parameter, allowing a remote attacker to bypass security restrictions. This could enable an attacker to modify another user's preferences.
Recommendations For IBM Rational Asset Manager version 7.5, consider restricting access to the UID parameter to prevent unauthorized modifications until a fix is available. As a temporary workaround, limit the ability to modify user preferences to authorized personnel only.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2023-00176
CVE-2011-4820

Affected Products

Ibm Rational Asset Manager