First published: Thu Dec 19 2013(Updated: )
IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP002, and 2.0.2 before 2.0.2.1-ICN-FP001 allows remote attackers to conduct clickjacking attacks via vectors involving FRAME elements.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Navigator | =2.0.0 | |
IBM Content Navigator | =2.0.1 | |
IBM Content Navigator | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5462 has a medium severity level due to its potential for clickjacking attacks.
To fix CVE-2013-5462, upgrade to IBM Content Navigator versions 2.0.1.2-ICN-FP002 or 2.0.2.1-ICN-FP001 or later.
CVE-2013-5462 affects IBM Content Navigator versions 2.0.0, 2.0.1, and 2.0.2 before their respective fixed versions.
CVE-2013-5462 allows attackers to conduct clickjacking attacks capable of tricking users into clicking on malicious elements.
There is no official workaround for CVE-2013-5462, and it is recommended to apply the necessary updates as soon as possible.