First published: Wed Feb 15 2017(Updated: )
IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM Reference #: 1997906.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Integration Bus for z/OS | =9.0 | |
IBM Integration Bus for z/OS | =10.0 | |
IBM WebSphere Message Broker | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9010 is considered to have a moderate severity level due to the potential for remote clickjacking attacks.
To fix CVE-2016-9010, apply the latest patches provided by IBM for affected versions of IBM WebSphere Message Broker and IBM Integration Bus.
CVE-2016-9010 affects IBM WebSphere Message Broker 8.0, 9.0, and 10.0 as well as IBM Integration Bus 9.0 and 10.0.
Yes, CVE-2016-9010 can lead to further attacks if clickjacking is successfully exploited, allowing attackers to manipulate user actions.
Users of affected versions of IBM WebSphere Message Broker and IBM Integration Bus who visit malicious websites are at risk from CVE-2016-9010.