CVE-2016-5984

Description

IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.206

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in InfoSphere Information Server 8.7Windows
Multiple Vulnerabilities are affected in InfoSphere Information Server 9.1Windows
Multiple Vulnerabilities are affected in InfoSphere Information Server 11.3Windows
Multiple Vulnerabilities are affected in InfoSphere Information Server 11.5Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234