CVE-2018-1432: CSRF

Published Jun 5, 2018
·
Updated

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social engineering or Cross-Site Request Forgery attacks. IBM X-Force ID: 139360.

Affected Software

4 affected components
IBM InfoSphere Information Server=9.1
IBM InfoSphere Information Server=11.3
IBM InfoSphere Information Server=11.5
IBM InfoSphere Information Server=11.7

Event History

Jun 5, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2018-1432?

CVE-2018-1432 is classified as a moderate severity vulnerability due to its potential exploitation via clickjacking.

2

How do I fix CVE-2018-1432?

To remediate CVE-2018-1432, update IBM InfoSphere Information Server to a patched version provided by IBM.

3

Which versions of IBM InfoSphere Information Server are affected by CVE-2018-1432?

CVE-2018-1432 affects IBM InfoSphere Information Server versions 9.1, 11.3, 11.5, and 11.7.

4

What type of attack can be executed using CVE-2018-1432?

CVE-2018-1432 can be exploited to perform clickjacking attacks that trick users into interacting with hidden elements.

5

Is user interaction required to exploit CVE-2018-1432?

Yes, user interaction is typically required for successful exploitation of CVE-2018-1432 as it relies on tricking users into clicking on hidden elements.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203