Vulnerability Name: | CVE-2014-4786 (CCN-95033) | ||||||||
Assigned: | 2014-09-08 | ||||||||
Published: | 2014-09-08 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue. | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N) 3.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-4786 Source: SECUNIA Type: UNKNOWN 60996 Source: CCN Type: IBM Security Bulletin 1682450 Multiple Vulnerabilities in IBM Initiate Master Data Service (CVE-2014-4789, CVE-2014-4788, CVE-2014-4787, CVE-2014-4786, CVE-2014-4785, CVE-2014-4784, CVE-2014-4783) Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21682450 Source: BID Type: Third Party Advisory, VDB Entry 69720 Source: CCN Type: BID-69720 IBM Initiate Master Data Service CVE-2014-4786 Unspecified Frame Injection Vulnerability Source: XF Type: UNKNOWN ibm-imds-cve20144786-phishing(95033) Source: XF Type: UNKNOWN ibm-imds-cve20144786-frame-injection(95033) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |