First published: Thu May 02 2019(Updated: )
IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 155195.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
API Connect CLI Plugins | >=2018.1.0<=2018.4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2015 is classified as a medium severity vulnerability due to its potential for clickjacking attacks.
To remediate CVE-2018-2015, update IBM API Connect to the latest version that is not affected by this vulnerability.
CVE-2018-2015 affects IBM API Connect versions 2018.1 and 2018.4.1.4.
Yes, CVE-2018-2015 can be exploited remotely if a victim is tricked into visiting a malicious website.
CVE-2018-2015 is associated with clickjacking attacks, allowing a remote attacker to hijack user click actions.