Release date:
Updated on:
Affected Systems:
IBM Rational ClearQuest 8.0.0.0-8.0.0.4
IBM Rational ClearQuest 7.1.2.0-7.1.2.8
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56946
CVE (CAN) ID: CVE-2012-4839, CVE-2012-5765
IBM Rational ClearQuest is a comprehensive software change and tracking management solution.
Input in the OSLC Interface System of IBM Rational ClearQuest 7.1.2.9 and earlier than 8.0.0.5 is incorrectly filtered and returned to users through frame phishing attacks, remote attackers can exploit this vulnerability to execute arbitrary HTML and script code in the browsers of affected users. The injection vulnerability allows unauthorized access to the database.
<* Source: vendor
Link: http://xforce.iss.net/xforce/xfdb/79068
Http://www.securelist.com/en/advisories/51598
Http://www-01.ibm.com/support/docview.wss? Uid = swg21620342
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
For this reason, IBM has released a Security Bulletin (swg21620342) and corresponding patches:
Swg21620342: Security Bulletin: ClearQuest Phishing Through Frames Vulnerability (CVE-2012-4839)
Link: http://www-01.ibm.com/support/docview.wss? Uid = swg21620342
Patch download:
8.0.0.5: http://www.ibm.com/support/docview.wss? & Uid = swg24032.169
7.1.2.9: http://www.ibm.com/support/docview.wss? Uid = swg24033977