Clickjacking Vulnerability in IBM Security Access Manager Appliance
CVE-2018-1803
6.1MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 13 December 2018
Summary
A vulnerability in IBM Security Access Manager Appliance allows remote attackers to hijack user click actions. By enticing users to navigate to a malicious site, attackers can exploit this flaw to perform unauthorized operations on behalf of victims, potentially leading to further security breaches. It is critical for organizations using affected versions to implement security measures to mitigate the risk of exploitation.
Affected Version(s)
Security Access Manager Appliance 9.0.1.0
Security Access Manager Appliance 9.0.2.0
Security Access Manager Appliance 9.0.3.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved