CVE-2020-4406
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.1.7.0 to 8.1.9.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.1.9.0 to 8.1.9.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.1.7.0 to 8.1.9.1 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.1.9.0 to 8.1.9.1 |
| Running on/with | Platform Versions |
|---|---|
Ibm Aix | All versions |
References (4)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.