CVE-2017-1551: Input Validation
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 131291.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1551?
CVE-2017-1551 is classified as a high severity vulnerability due to the potential for remote attack leading to clickjacking.
How do I fix CVE-2017-1551?
To fix CVE-2017-1551, update IBM API Connect to version 5.0.7.3 or later.
What versions of IBM API Connect are affected by CVE-2017-1551?
IBM API Connect versions 5.0.0.0 through 5.0.7.2 are affected by CVE-2017-1551.
What type of attack can CVE-2017-1551 potentially lead to?
CVE-2017-1551 can potentially lead to clickjacking attacks, allowing an attacker to hijack a victim's click actions.
Is user interaction required to exploit CVE-2017-1551?
Yes, exploitation of CVE-2017-1551 requires the victim to visit a malicious website as part of the attack.