5.4
CVE-2020-4547
- EPSS 0.09%
- Published 27.01.2021 17:15:11
- Last modified 21.11.2024 05:32:52
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 183315.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Collaborative Lifecycle Management Version6.0.2
Ibm ≫ Collaborative Lifecycle Management Version6.0.6
Ibm ≫ Collaborative Lifecycle Management Version6.0.6.1
Ibm ≫ Engineering Insights Version7.0
Ibm ≫ Engineering Lifecycle Management Version7.0
Ibm ≫ Engineering Requirements Management Doors Next Version6.0.2
Ibm ≫ Engineering Requirements Management Doors Next Version6.0.6
Ibm ≫ Engineering Requirements Management Doors Next Version6.0.6.1
Ibm ≫ Engineering Requirements Management Doors Next Version7.0
Ibm ≫ Engineering Test Management Version7.0.0
Ibm ≫ Engineering Workflow Management Version6.0.2
Ibm ≫ Engineering Workflow Management Version6.0.6
Ibm ≫ Engineering Workflow Management Version6.0.6.1
Ibm ≫ Engineering Workflow Management Version7.0
Ibm ≫ Engineering Workflow Management Version7.0.2
Ibm ≫ Rational Engineering Lifecycle Manager Version6.0.2
Ibm ≫ Rational Engineering Lifecycle Manager Version6.0.6
Ibm ≫ Rational Engineering Lifecycle Manager Version6.0.6.1
Ibm ≫ Rational Quality Manager Version6.0.2
Ibm ≫ Rational Quality Manager Version6.0.6
Ibm ≫ Rational Quality Manager Version6.0.6.1
Ibm ≫ Rhapsody Design Manager Version6.0.2
Ibm ≫ Rhapsody Design Manager Version6.0.6
Ibm ≫ Rhapsody Design Manager Version6.0.6.1
Ibm ≫ Rhapsody Design Manager Version7.0
Ibm ≫ Rhapsody Model Manager Version6.0.2
Ibm ≫ Rhapsody Model Manager Version6.0.6
Ibm ≫ Rhapsody Model Manager Version6.0.6.1
Ibm ≫ Rhapsody Model Manager Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.226 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
psirt@us.ibm.com | 5.4 | 2.3 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.