CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:H/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
92.3%
The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.
Vendor | Product | Version | CPE |
---|---|---|---|
samba | samba | 3.0.20b | cpe:/a:samba:samba:3.0.20b::: |
samba | samba | 3.0.25 | cpe:/a:samba:samba:3.0.25:rc3:: |
samba | samba | 3.0.26 | cpe:/a:samba:samba:3.0.26:a:: |
samba | samba | 3.4.11 | cpe:/a:samba:samba:3.4.11::: |
samba | samba | 3.0.28 | cpe:/a:samba:samba:3.0.28::: |
samba | samba | 3.3.12 | cpe:/a:samba:samba:3.3.12::: |
samba | samba | 3.0.37 | cpe:/a:samba:samba:3.0.37::: |
samba | samba | 3.2.14 | cpe:/a:samba:samba:3.2.14::: |
samba | samba | 3.0.25 | cpe:/a:samba:samba:3.0.25:rc2:: |
samba | samba | 3.0.25 | cpe:/a:samba:samba:3.0.25:pre2:: |
lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.html
lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.html
lists.opensuse.org/opensuse-updates/2013-02/msg00029.html
lists.opensuse.org/opensuse-updates/2013-02/msg00033.html
rhn.redhat.com/errata/RHSA-2013-1310.html
rhn.redhat.com/errata/RHSA-2013-1542.html
rhn.redhat.com/errata/RHSA-2014-0305.html
www.debian.org/security/2013/dsa-2617
www.samba.org/samba/security/CVE-2013-0213
www.securityfocus.com/bid/57631
www.ubuntu.com/usn/USN-2922-1
h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993