CVE-2024-30109

HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended.
Configurations

No configuration.

History

28 Jun 2024, 10:27

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-28 06:15

Updated : 2024-06-28 10:27


NVD link : CVE-2024-30109

Mitre link : CVE-2024-30109

CVE.ORG link : CVE-2024-30109


JSON object : View

Products Affected

No product.

CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames