Phishing Vulnerability in IBM Rational ClearQuest Web Client by IBM
CVE-2012-4839 
Currently unrated
What is CVE-2012-4839?
The OSLC interface in IBM Rational ClearQuest Web Client exposes a weakness that allows remote attackers to execute phishing attacks through the use of a FRAME element. This vulnerability affects versions prior to 7.1.2.9 in the 7.1.2.x series and prior to 8.0.0.5 in the 8.0.0.x series, enabling potential exploitation of the interface to mislead users into providing sensitive information. Organizations using vulnerable versions of this product should consider applying the necessary patches to mitigate the risk.