Описание
The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:ibm:rational_clearquest:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:7.1.2.8:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:a:ibm:rational_clearquest:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:rational_clearquest:8.0.0.4:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00227
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
github
больше 3 лет назад
The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.
EPSS
Процентиль: 45%
0.00227
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-noinfo