CVE-2012-4839: Medium severity IBM Rational ClearQuest vulnerability
Published Dec 20, 2012
·Updated
The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.
Affected Software
14 affected components
IBM Rational ClearQuest=7.1.2
IBM Rational ClearQuest=7.1.2.1
IBM Rational ClearQuest=7.1.2.2
IBM Rational ClearQuest=7.1.2.3
IBM Rational ClearQuest=7.1.2.4
IBM Rational ClearQuest=7.1.2.5
IBM Rational ClearQuest=7.1.2.6
IBM Rational ClearQuest=7.1.2.7
IBM Rational ClearQuest=7.1.2.8
IBM Rational ClearQuest=8.0.0
IBM Rational ClearQuest=8.0.0.1
IBM Rational ClearQuest=8.0.0.2
IBM Rational ClearQuest=8.0.0.3
IBM Rational ClearQuest=8.0.0.4
Event History
Dec 20, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4839?
CVE-2012-4839 has a medium severity score, indicating it can potentially allow phishing attacks.
2
How do I fix CVE-2012-4839?
To fix CVE-2012-4839, update IBM Rational ClearQuest to version 7.1.2.9 or higher, or 8.0.0.5 or higher.
3
What versions of IBM Rational ClearQuest are affected by CVE-2012-4839?
CVE-2012-4839 affects IBM Rational ClearQuest versions 7.1.2.0 to 7.1.2.8 and 8.0.0.0 to 8.0.0.4.
4
What type of attack is enabled by CVE-2012-4839?
CVE-2012-4839 allows remote attackers to conduct phishing attacks through the OSLC interface in the Web Client.
5
Is there a workaround for CVE-2012-4839 if I cannot update?
There is no official workaround for CVE-2012-4839; upgrading to the patched versions is recommended.