CVE-2013-0518: Input Validation
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 does not refuse to be rendered in different-origin frames, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0518?
CVE-2013-0518 is classified as a medium severity vulnerability affecting IBM Sterling Secure Proxy.
How do I fix CVE-2013-0518?
To remediate CVE-2013-0518, upgrade IBM Sterling Secure Proxy to version 3.3.01.23 Interim Fix 1, 3.4.0.6 Interim Fix 1, or 3.4.1.7 or later.
What types of attacks are possible due to CVE-2013-0518?
CVE-2013-0518 makes IBM Sterling Secure Proxy vulnerable to clickjacking attacks.
Which versions of IBM Sterling Secure Proxy are affected by CVE-2013-0518?
CVE-2013-0518 affects versions 3.2.0, 3.3.0.1, 3.4.0, and 3.4.1 prior to their respective interim fixes.
Is authentication compromised by CVE-2013-0518?
CVE-2013-0518 does not compromise authentication but allows attackers to manipulate the user interface through clickjacking.