Lucene search

K
ibmIBM2FD4612A92F3573948520317A8CCE1B0F3437D772EEDFE163CC2194B16370115
HistoryJul 23, 2021 - 7:55 a.m.

Security Bulletin: HTTP Header Vulnerability Affects IBM Sterling Connect:Direct Browser User Interface (CVE-2021-20560)

2021-07-2307:55:53
www.ibm.com
13

0.001 Low

EPSS

Percentile

28.9%

Summary

There are issue with HTTP header ‘X-Frame-Options’ not present. IBM Sterling Connect:Direct Browser has addressed the applicable CVEs.

Vulnerability Details

CVEID:CVE-2021-20560
**DESCRIPTION:**IBM Sterling Connect:Direct Browser User Interface could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199229 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Sterling Connect:Direct Browser User Interface 1.5.0.2
Sterling Connect:Direct Browser User Interface 1.4.1.1

Remediation/Fixes

Apply 1.5.0.2 iFix-27, available in cumulative iFix028 on Fix Central

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

28.9%

Related for 2FD4612A92F3573948520317A8CCE1B0F3437D772EEDFE163CC2194B16370115