IBM Rational Quality Manager Lets Remote Users Conduct Clickjacking Attacks
|
SecurityTracker Alert ID: 1034568 |
SecurityTracker URL: http://securitytracker.com/id/1034568
|
CVE Reference:
CVE-2015-1928
(Links to External Site)
|
Date: Jan 4 2016
|
Impact:
Modification of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 3.0.1, 3.0.1.6, 4.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 5.0, 5.0.1, 5.0.2, 6.0
|
Description:
A vulnerability was reported in IBM Rational Quality Manager. A remote user can conduct click-jacking attacks.
A remote user can hijack a target user's mouse clicks to take actions on the site acting as the target user.
The vulnerability resides in the IBM Jazz Foundation component.
|
Impact:
A remote user can conduct clickjacking attacks.
|
Solution:
IBM has issued a fix (3.0.1.6 iFix 7, 4.0.7 iFix9, 5.0.2 iFix11, 6.0.0 iFix4).
The IBM advisory is available at:
http://www-01.ibm.com/support/docview.wss?uid=swg21973200
|
Vendor URL: www-01.ibm.com/support/docview.wss?uid=swg21973200 (Links to External Site)
|
Cause:
Access control error
|
Underlying OS: Linux (Any), UNIX (AIX), UNIX (Solaris - SunOS), Windows (Any), z/OS
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|