CVE-2018-1478: Input Validation
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 140760.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1478?
CVE-2018-1478 has been assigned a medium severity rating due to the potential for clickjacking attacks against IBM BigFix Platform users.
How do I fix CVE-2018-1478?
To fix CVE-2018-1478, upgrade to IBM BigFix Platform version 9.5.10 or later, as this version addresses the vulnerability.
What versions of IBM BigFix Platform are affected by CVE-2018-1478?
CVE-2018-1478 affects IBM BigFix Platform versions 9.2.0 through 9.2.14 and 9.5 through 9.5.9.
Can CVE-2018-1478 be exploited remotely?
Yes, CVE-2018-1478 can be exploited remotely if a victim is persuaded to visit a malicious website.
What are the implications of CVE-2018-1478 for users?
The implications of CVE-2018-1478 for users include the risk of unauthorized actions being performed on their behalf through clickjacking attacks.