Clickjacking Vulnerability in IBM BigFix Platform
CVE-2018-1478

6.1MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
12 December 2018

Summary

The IBM BigFix Platform versions 9.2.0 through 9.2.14 and 9.5 through 9.5.9 are susceptible to a clickjacking vulnerability. This security weakness can be exploited by remote attackers who entice users to visit a malicious website. Once on the site, attackers can hijack the user's click actions, potentially enabling them to perform unauthorized actions on behalf of the victim. The vulnerability presents significant risks as it may facilitate further attacks against compromised user accounts.

Affected Version(s)

BigFix Platform 9.5.9

BigFix Platform 9.2.0

BigFix Platform 9.2.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.