PT-2018-12437 · Ibm · Ibm Infosphere Information Server
Publicado
2018-06-05
·
Atualizado
2020-08-24
·
CVE-2018-1432
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
IBM InfoSphere Information Server versions 9.1, 11.3, 11.5, 11.7
Description
The issue allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page, enabling Clickjacking attacks for phishing, frame sniffing, social engineering, or Cross-Site Request Forgery attacks.
Recommendations
For IBM InfoSphere Information Server versions 9.1, 11.3, 11.5, 11.7, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Clickjacking
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibm Infosphere Information Server