Vulnerabilities > CVE-2012-4839 - Unspecified vulnerability in IBM Rational Clearquest
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN ibm
nessus
Summary
The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | IBM_RATIONAL_CLEARQUEST_7_1_2_9.NASL |
description | The remote host has a version of IBM Rational ClearQuest 7.1.x prior to 7.1.2.9 / 8.0.0.x prior to 8.0.0.5 installed. It is, therefore, affected by the following vulnerabilities : - An unspecified input validation error exists related to the Open Services for Lifecycle Collaboration (OSLC) system that can allow cross-site scripting attacks. Note that this issue only affects systems if the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 63323 |
published | 2012-12-21 |
reporter | This script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/63323 |
title | IBM Rational ClearQuest 7.1.x < 7.1.2.9 / 8.0.0.x < 8.0.0.5 Multiple Vulnerabilities (credentialed check) |
code |
|
References
- http://www.securitytracker.com/id?1027889
- http://www.securitytracker.com/id?1027889
- http://www-01.ibm.com/support/docview.wss?uid=swg21620342
- http://www-01.ibm.com/support/docview.wss?uid=swg21620342
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79068
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79068