First published: Wed Feb 23 2022(Updated: )
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 213968.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | >=9.0.0.0<9.0.5.12 | |
Ibm Websphere Application Server | >=17.0.0.3<=22.0.0.2 | |
IBM WebSphere Application Server Liberty | <=17.0.0.3 - 22.0.0.2 | |
Ibm Websphere Application Server | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39038 is a vulnerability in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty that could allow a remote attacker to hijack the clicking action of the victim.
CVE-2021-39038 works by persuading a victim to visit a malicious website, which allows a remote attacker to exploit the vulnerability and hijack the clicking action of the victim.
The severity of CVE-2021-39038 is medium, with a severity value of 5.4.
A remote attacker can exploit CVE-2021-39038 by tricking a victim into visiting a malicious website.
More information about CVE-2021-39038 can be found on the IBM X-Force Exchange website and the IBM support pages.