CVE-2020-4406

IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:spectrum_protect_client:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:ibm:spectrum_protect_client:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:ibm:spectrum_protect_for_space_management:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:ibm:spectrum_protect_for_space_management:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:32

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/179488 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/179488 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/6221448 - Vendor Advisory () https://www.ibm.com/support/pages/node/6221448 - Vendor Advisory

Information

Published : 2020-06-15 14:15

Updated : 2024-11-21 05:32


NVD link : CVE-2020-4406

Mitre link : CVE-2020-4406

CVE.ORG link : CVE-2020-4406


JSON object : View

Products Affected

ibm

  • aix
  • spectrum_protect_client
  • spectrum_protect_for_space_management

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames