CVE-2021-39038

Description

IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victims click actions and possibly launch further attacks against the victim. IBM X-Force ID: 213968.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.034

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-39038 are fixed in IBM WebSphere 22.0.0.3Windows
Vulnerabilities CVE-2021-39038 are fixed in IBM WebSphere 9.0.5.12Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.2Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 8.2.0.2Windows
Vulnerabilities CVE-2021-26296,CVE-2021-39038,CVE-2022-24839 are affected in IBM TXSeries for Multiplatforms 9.1.0.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234