Show plain JSON{"id": "CVE-2014-3009", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 3.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 6.8, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2014-08-01T05:12:51.900", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21677306", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/92952", "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21677306", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/92952", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-20"}]}], "descriptions": [{"lang": "en", "value": "The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site."}, {"lang": "es", "value": "El componente GDS en IBM InfoSphere Master Data Management - Collaborative Edition 10.0 hasta 11.0 y InfoSphere Master Data Management Server for Product Information Management 9.0 y 9.1 no maneja debidamente los elementos FRAME, lo que facilita a usuarios remotos autenticados realizar ataques de phishing a trav\u00e9s de un sitio web manipulado."}], "lastModified": "2025-04-12T10:46:40.837", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management_server_for_product_information_management:9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "05F44C2D-F7E1-46CB-A319-B7D21121DA53"}, {"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management_server_for_product_information_management:9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B31F0A6-7796-42C2-8911-1B0D1B0A26A8"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management:10.0:*:*:*:collaborative:*:*:*", "vulnerable": true, "matchCriteriaId": "C2C18237-D43D-4423-B03D-0C02EE26C2CE"}, {"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management:10.1:*:*:*:collaborative:*:*:*", "vulnerable": true, "matchCriteriaId": "38FBFED0-F44F-48BF-96C0-33025890C4D5"}, {"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management:11.0:*:*:*:collaborative:*:*:*", "vulnerable": true, "matchCriteriaId": "6FE73850-0816-4C28-B114-4FEB2A0B6586"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}