First published: Fri Nov 01 2019(Updated: )
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159186.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SmartCloud Analytics Log Analysis | >=1.3.1<=1.3.5 | |
<=1.3.1 | ||
<=1.3.2 | ||
<=1.3.3 | ||
<=1.3.4 | ||
<=1.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-4215.
CVE-2019-4215 has a severity level of medium (6.1).
IBM SmartCloud Analytics versions 1.3.1 through 1.3.5 are affected by CVE-2019-4215.
A remote attacker can exploit CVE-2019-4215 by persuading a victim to visit a malicious website, which hijacks the victim's click actions and potentially launches further attacks.
To fix the vulnerability in IBM SmartCloud Analytics, upgrade to a version beyond 1.3.5.