CVE-2018-2015: Input Validation
IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 155195.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2015?
CVE-2018-2015 is classified as a medium severity vulnerability due to its potential for clickjacking attacks.
How do I fix CVE-2018-2015?
To remediate CVE-2018-2015, update IBM API Connect to the latest version that is not affected by this vulnerability.
What versions of IBM API Connect are affected by CVE-2018-2015?
CVE-2018-2015 affects IBM API Connect versions 2018.1 and 2018.4.1.4.
Can CVE-2018-2015 be exploited remotely?
Yes, CVE-2018-2015 can be exploited remotely if a victim is tricked into visiting a malicious website.
What type of attack is CVE-2018-2015 associated with?
CVE-2018-2015 is associated with clickjacking attacks, allowing a remote attacker to hijack user click actions.