Vulnerability Name: | CVE-2014-3009 (CCN-92952) | ||||||||
Assigned: | 2014-08-01 | ||||||||
Published: | 2014-08-01 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site. | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 2.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3009 Source: CCN Type: IBM Security Bulletin 1677306 Phishing through frames vulnerability in the GDS component of IBM InfoSphere Master Data Management - Collaborative Edition (CVE-2014-3009) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21677306 Source: CCN Type: IBM Security Bulletin 1681645 Session Identifier Not Updated vulnerability in GDS component of IBM InfoSphere Master Data Management - Collaborative Edition (CVE-2014-3009) Source: CCN Type: BID-69004 Multiple IBM InfoSphere Master Data Management Products Unspecified Frame Injection Vulnerability Source: XF Type: UNKNOWN ibm-infosphere-cve20143009-phishing(92952) Source: XF Type: UNKNOWN ibm-imdm-cve20143009-phish(92952) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |