First published: Sat Jan 17 2015(Updated: )
IBM Security Network Protection 5.1.x and 5.2.x before 5.2.0.0 FP5 and 5.3.x before 5.3.0.0 FP1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Network Protection | =5.1 | |
IBM Security Network Protection | =5.1.1 | |
IBM Security Network Protection | =5.1.2 | |
IBM Security Network Protection | =5.1.2.1 | |
IBM Security Network Protection | =5.2 | |
IBM Security Network Protection | =5.3 | |
IBM Security Network Protection XGS 3100 | ||
IBM Security Network Protection 4100 Firmware | ||
IBM Security Network Protection 5100 | ||
IBM Security Network Protection 7100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6197 is classified as a medium severity vulnerability that allows remote attackers to perform clickjacking attacks.
To mitigate CVE-2014-6197, upgrade IBM Security Network Protection to versions 5.2.0.0 FP5 or 5.3.0.0 FP1 or later.
CVE-2014-6197 affects IBM Security Network Protection versions 5.1.x and 5.2.x before 5.2.0.0 FP5, and 5.3.x before 5.3.0.0 FP1.
CVE-2014-6197 is associated with clickjacking attacks, where users can be tricked into clicking on concealed buttons.
There is no documented workaround for CVE-2014-6197; upgrading to a fixed version is recommended.