Frame Injection Vulnerability in IBM Emptoris Sourcing Portfolio and Spend Analysis
CVE-2014-4790

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 August 2014

Summary

IBM Emptoris Sourcing Portfolio and Spend Analysis encounter a security vulnerability due to insufficient restrictions on the use of FRAME elements. This flaw allows remote authenticated users to initiate phishing attacks or bypass intended access controls, potentially exposing sensitive information through crafted web pages. Users of affected versions should prioritize updates to mitigate these risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.