IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21902807 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-06-28 15:59
Updated : 2015-06-29 09:30
NVD link : CVE-2015-0127
Mitre link : CVE-2015-0127
JSON object : View
CWE
CWE-254
7PK - Security Features
Products Affected
ibm
- leads