First published: Thu Jun 27 2019(Updated: )
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Information Server | =11.3 | |
Ibm Infosphere Information Server | =11.5 | |
Ibm Infosphere Information Server | =11.7 | |
IBM InfoSphere Information Governance Catalog | =11.3 | |
IBM InfoSphere Information Governance Catalog | =11.5 | |
IBM InfoSphere Information Governance Catalog | =11.7 | |
Ibm Infosphere Information Server On Cloud | =11.5 | |
Ibm Infosphere Information Server On Cloud | =11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4237 is a Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7, which allows an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page.
IBM InfoSphere Information Server versions 11.3, 11.5, and 11.7 are affected by CVE-2019-4237.
CVE-2019-4237 has a severity level of medium with a CVSS score of 5.4.
To fix CVE-2019-4237, IBM recommends applying the necessary patches and updates provided by the vendor.
You can find more information about CVE-2019-4237 on the IBM X-Force Exchange website (link: https://exchange.xforce.ibmcloud.com/vulnerabilities/159419) and the IBM support website (link: https://www.ibm.com/support/docview.wss?uid=ibm10879825).