3.5

CVE-2015-1980

IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Infosphere Master Data Management Version 9.1 SwEdition collaborative
Ibm ≫ Infosphere Master Data Management Version 10.1 SwEdition collaborative
Ibm ≫ Infosphere Master Data Management Version 11.0 SwEdition collaborative
Ibm ≫ Infosphere Master Data Management Version 11.3 SwEdition collaborative
Ibm ≫ Infosphere Master Data Management Version 11.4 SwEdition collaborative
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.79% 0.513
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www-01.ibm.com/support/docview.wss?uid=swg21960244
Patch
Vendor Advisory
http://www.securityfocus.com/bid/75143