VulnerabilityModified
CVE-2012-4839
The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.
MEDIUM 4.3EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- ibm/rational clearquest
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21620342Vendor Advisory
- http://www.securitytracker.com/id?1027889
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79068
- http://www-01.ibm.com/support/docview.wss?uid=swg21620342Vendor Advisory
- http://www.securitytracker.com/id?1027889
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79068
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.