First published: Mon Jul 09 2018(Updated: )
IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 143744.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
API Connect CLI Plugins | >=5.0.0.0<=5.0.8.3 | |
API Connect CLI Plugins | >=2018.1<=2018.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1599 has been classified with a high severity due to its potential to allow remote clickjacking attacks.
To fix CVE-2018-1599, upgrade IBM API Connect to version 5.0.8.4 or later.
Exploitation of CVE-2018-1599 can lead to unauthorized actions being performed on behalf of the victim, potentially compromising sensitive information.
CVE-2018-1599 affects IBM API Connect versions 5.0.0.0 through 5.0.8.3 and 2018.1 through 2018.3.4.
CVE-2018-1599 can facilitate clickjacking attacks, where a victim is misled into performing unintended actions on a web application.