SB2019051107 - Improper restriction of rendered UI layers or frames in IBM Security Information Queue



SB2019051107 - Improper restriction of rendered UI layers or frames in IBM Security Information Queue

Published: May 11, 2019 Updated: May 30, 2023

Security Bulletin ID SB2019051107
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2019-4217)

The vulnerability allows a remote attacker to hijack the clicking action of the victim.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trick the victim into visiting malicious Web site to exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.