First published: Thu Jul 18 2024(Updated: )
HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BigFix Security Compliance Analytics |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-30126 is considered medium due to the potential for website spoofing attacks.
To fix CVE-2024-30126, configure the web server to include the X-Frame-Options HTTP header in responses.
The potential impacts of CVE-2024-30126 include unauthorized actions by users on the affected website due to clickjacking attacks.
CVE-2024-30126 affects users of HCL BigFix Compliance that do not implement proper X-Frame-Options HTTP headers.
A temporary workaround for CVE-2024-30126 is to educate users to avoid clicking on suspicious links that may leverage clickjacking.