CVE-2014-3009: Input Validation
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3009?
CVE-2014-3009 is classified as a moderate severity vulnerability which can lead to unauthorized access when exploited.
How do I fix CVE-2014-3009?
To fix CVE-2014-3009, ensure that you apply the latest patches or updates provided by IBM for your specific version of InfoSphere Master Data Management.
Which versions are affected by CVE-2014-3009?
CVE-2014-3009 affects IBM InfoSphere Master Data Management - Collaborative Edition versions 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management versions 9.0 and 9.1.
What types of attacks can CVE-2014-3009 facilitate?
CVE-2014-3009 can facilitate attacks that exploit improper handling of FRAME elements, potentially allowing remote authenticated users to conduct cross-site scripting attacks.
Is CVE-2014-3009 related to cross-site scripting vulnerabilities?
Yes, CVE-2014-3009 is related to cross-site scripting vulnerabilities due to its exploitation of improperly handled FRAME elements.