PT-2020-20707 · Micro Focus · Micro Focus Service Manager Release Control

Published

2020-03-09

·

Updated

2021-07-21

·

CVE-2020-9517

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Micro Focus Service Manager Release Control versions 9.50 through 9.60
Description The issue is related to an improper restriction of rendered UI layers or frames, which may allow malicious users to perform UI redress attacks.
Recommendations For versions 9.50 and 9.60, consider restricting access to sensitive UI components to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling any features that rely on rendered UI layers or frames until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9517

Affected Products

Micro Focus Service Manager Release Control