Fixes are available
Rational ClearQuest Fix Pack 9 (8.0.1.9) for 8.0.1
Rational ClearQuest Fix Pack 10 (8.0.1.10) for 8.0.1
Rational ClearQuest Fix Pack 11 (8.0.1.11) for 8.0.1
Rational ClearQuest Fix Pack 12 (8.0.1.12) for 8.0.1
Rational ClearQuest Fix Pack 13 (8.0.1.13) for 8.0.1
Rational ClearQuest Fix Pack 14 (8.0.1.14) for 8.0.1
Rational ClearQuest Fix Pack 15 (8.0.1.15) for 8.0.1
Rational ClearQuest Fix Pack 16 (8.0.1.16) for 8.0.1
Rational ClearQuest Fix Pack 17 (8.0.1.17) for 8.0.1
Rational ClearQuest Fix Pack 18 (8.0.1.18) for 8.0.1
Rational ClearQuest Fix Pack 19 (8.0.1.19) for 8.0.1
Rational ClearQuest Fix Pack 20 (8.0.1.20) for 8.0.1
Rational ClearQuest Fix Pack 21 (8.0.1.21) for 8.0.1
Rational ClearQuest Fix Pack 22 (8.0.1.22) for 8.0.1
Rational ClearQuest Fix Pack 23 (8.0.1.23) for 8.0.1
Rational ClearQuest Fix Pack 24 (8.0.1.24) for 8.0.1
Rational ClearQuest Fix Pack 25 (8.0.1.25) for 8.0.1
APAR status
Closed as program error.
Error description
This issue is very quick and easy to reproduce. - Use out of the box Defectracking schema with SAMPL database. - Create REST URL autologin such as http://localhost/cqweb/restapi/8.0.0/SAMPL?format=HTML&loginId=a dmin&password=password -Logout CQ and run the URI. - Verify the browser URL Please note that the version 8.0.1.6 is also affected The tests on the following versions work well: 8.0.1.4 8.0.0.11 8.0.0.10
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: * * ClearQuest * **************************************************************** * PROBLEM DESCRIPTION: * * When using the ClearQuest REST autologin API, if there is a * * credential provided in URL, the password keeps being * * displayed on the URL. * **************************************************************** * RECOMMENDATION: * ****************************************************************
Problem conclusion
A fix is available in ClearQuest 8.0.1.9. When using the ClearQuest REST autologin API, the password will no longer be kept in the URL. The password is now replaced with a one time token.
Temporary fix
Comments
APAR Information
APAR number
PI33852
Reported component name
CLEARQUEST WIN
Reported component ID
5724G3600
Reported release
801
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2015-01-30
Closed date
2015-09-22
Last modified date
2015-09-22
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
CLEARQUEST WIN
Fixed component ID
5724G3600
Applicable component levels
R801 PSY
UP
Document Information
Modified date:
14 October 2021