First published: Wed Oct 02 2013(Updated: )
IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to conduct clickjacking attacks by creating an overlay interface on top of the Web Console interface.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Analyzer | =8.0 | |
IBM InfoSphere Information Analyzer | =8.1 | |
IBM InfoSphere Information Analyzer | =8.5 | |
IBM InfoSphere Information Analyzer | =8.5.0.1 | |
IBM InfoSphere Information Analyzer | =8.5.0.2 | |
IBM InfoSphere Information Analyzer | =8.5.0.3 | |
IBM InfoSphere Information Analyzer | =8.7 | |
IBM InfoSphere Information Analyzer | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4066 is considered a medium severity vulnerability due to its potential to facilitate clickjacking attacks.
To fix CVE-2013-4066, you should update your IBM InfoSphere Information Server to a version that is not affected by this vulnerability.
CVE-2013-4066 affects IBM InfoSphere Information Server versions 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1.
Yes, CVE-2013-4066 can be exploited remotely by attackers conducting clickjacking attacks.
Exploitation of CVE-2013-4066 can lead to unauthorized actions being performed by users unknowingly, potentially compromising sensitive data.