Improper UI Layer Restriction in Micro Focus Service Manager
CVE-2020-9517

5.4MEDIUM

Key Information:

Vendor
CVE Published:
9 March 2020

What is CVE-2020-9517?

Employees using Micro Focus Service Manager Release Control versions 9.50 and 9.60 may be at risk due to improper restrictions on rendered UI layers or frames. This vulnerability allows malicious actors to carry out UI redress attacks, potentially leading to unauthorized actions or data exposure. Companies using this software should take immediate steps to secure their systems and patch affected products to prevent exploitation.

Affected Version(s)

Service Manager 9.50, 9.60

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.