Cross-frame scripting in IBM Corporation products - CVE-2018-1432

 

Cross-frame scripting in IBM Corporation products - CVE-2018-1432

Published: June 5, 2018


Vulnerability identifier: #VU13182
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1432
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute a cross-frame scripting (XFS) attack.

The weakness exists due to insufficient protections for HTML inline frames (iframes). A remote attacker can trick the victim into visiting a specially crafted website, load valid content from the target system within an HTML iframe and attempt to conduct cross-site scripting, cross-site request forgery, clickjacking, or phishing attacks.

Affected software

IBM InfoSphere Information Server Metadata Workbench
IBM InfoSphere Information Server Business Glossary
IBM InfoSphere Information Server
IBM InfoSphere Data Quality Console
IBM InfoSphere Information Governance Catalog
IBM InfoSphere Data Click
IBM InfoSphere Metadata Asset Manager
IBM InfoSphere Information Analyzer
IBM InfoSphere Data Quality Exception Console
IBM InfoSphere Information Server for Cloud

How to mitigate CVE-2018-1432

Install update from vendor's website.


External References

Related Security Bulletins