CVE-2024-30109: Lack of Clickjacking Protection vulnerability affects DRYiCE AEX v10
HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30109?
CVE-2024-30109 is classified with a medium severity due to its potential for exploitation through clickjacking.
How do I fix CVE-2024-30109?
To fix CVE-2024-30109, implement appropriate clickjacking protections such as the X-Frame-Options or Content Security Policy headers.
What type of vulnerability is CVE-2024-30109?
CVE-2024-30109 is a clickjacking vulnerability affecting the HCL DRYiCE AEX web application.
Who is affected by CVE-2024-30109?
Users of the HCL DRYiCE AEX application are affected by CVE-2024-30109 due to inadequate clickjacking protection.
Can CVE-2024-30109 lead to data breaches?
Yes, CVE-2024-30109 can potentially lead to unauthorized actions being taken on behalf of users, which may result in data breaches.