Lucene search

K
cveIbmCVE-2014-4778
HistoryMay 25, 2015 - 2:59 p.m.

CVE-2014-4778

2015-05-2514:59:02
CWE-20
ibm
web.nvd.nist.gov
23
cve-2014-4778
ibm
license metric tool
endpoint manager
software use analysis
clickjacking
vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

52.4%

IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.

Affected configurations

Nvd
Node
ibmendpoint_manager_familyMatch9.0.1
OR
ibmendpoint_manager_familyMatch9.1.0
OR
ibmlicense_metric_toolMatch9.0
OR
ibmlicense_metric_toolMatch9.0.1
OR
ibmlicense_metric_toolMatch9.1.0.1
VendorProductVersionCPE
ibmendpoint_manager_family9.0.1cpe:2.3:a:ibm:endpoint_manager_family:9.0.1:*:*:*:*:*:*:*
ibmendpoint_manager_family9.1.0cpe:2.3:a:ibm:endpoint_manager_family:9.1.0:*:*:*:*:*:*:*
ibmlicense_metric_tool9.0cpe:2.3:a:ibm:license_metric_tool:9.0:*:*:*:*:*:*:*
ibmlicense_metric_tool9.0.1cpe:2.3:a:ibm:license_metric_tool:9.0.1:*:*:*:*:*:*:*
ibmlicense_metric_tool9.1.0.1cpe:2.3:a:ibm:license_metric_tool:9.1.0.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

52.4%

Related for CVE-2014-4778