Clickjacking Vulnerability in IBM API Connect Products
CVE-2020-4195

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
12 May 2020

Summary

IBM API Connect versions 2018.4.1.0 to 2018.4.1.10 are susceptible to a clickjacking vulnerability that allows remote attackers to compromise user interactions. By luring victims to malicious websites, attackers can manipulate user click actions, potentially facilitating further exploits against the victim. This poses significant risks to user data and application integrity, emphasizing the need for prompt security measures.

Affected Version(s)

API Connect 2018.4.1.0

API Connect 2018.4.1.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.