CVE-2015-4960: Medium severity ibm infosphere master data management vulnerability
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4960?
CVE-2015-4960 is classified as a medium-severity vulnerability due to its potential for clickjacking attacks.
How do I fix CVE-2015-4960?
To fix CVE-2015-4960, update IBM InfoSphere Master Data Management to versions 11.0.0.0 IF11, 11.3.0.0 IF7, or 11.4.0.4 IF1.
Who is affected by CVE-2015-4960?
CVE-2015-4960 affects users of IBM InfoSphere Master Data Management versions 9.1, 10.1, 11.0 prior to IF11, 11.3 prior to IF7, and 11.4 prior to IF1.
What type of attack does CVE-2015-4960 enable?
CVE-2015-4960 enables remote authenticated users to conduct clickjacking attacks via a crafted website.
Is user authentication sufficient to mitigate CVE-2015-4960?
No, user authentication alone is not sufficient to mitigate CVE-2015-4960 as it specifically targets authenticated users.