Lucene search

K
nvd[email protected]NVD:CVE-2015-0127
HistoryJun 28, 2015 - 10:59 p.m.

CVE-2015-0127

2015-06-2822:59:05
CWE-254
web.nvd.nist.gov
3

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

29.8%

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.

Affected configurations

Nvd
Node
ibmleadsMatch7.1.0
OR
ibmleadsMatch7.1.1
OR
ibmleadsMatch7.5.0
OR
ibmleadsMatch8.1.0
OR
ibmleadsMatch8.2.0
OR
ibmleadsMatch8.5.0
OR
ibmleadsMatch8.6.0
OR
ibmleadsMatch9.0.0
OR
ibmleadsMatch9.1.0
OR
ibmleadsMatch9.1.1
VendorProductVersionCPE
ibmleads7.1.0cpe:2.3:a:ibm:leads:7.1.0:*:*:*:*:*:*:*
ibmleads7.1.1cpe:2.3:a:ibm:leads:7.1.1:*:*:*:*:*:*:*
ibmleads7.5.0cpe:2.3:a:ibm:leads:7.5.0:*:*:*:*:*:*:*
ibmleads8.1.0cpe:2.3:a:ibm:leads:8.1.0:*:*:*:*:*:*:*
ibmleads8.2.0cpe:2.3:a:ibm:leads:8.2.0:*:*:*:*:*:*:*
ibmleads8.5.0cpe:2.3:a:ibm:leads:8.5.0:*:*:*:*:*:*:*
ibmleads8.6.0cpe:2.3:a:ibm:leads:8.6.0:*:*:*:*:*:*:*
ibmleads9.0.0cpe:2.3:a:ibm:leads:9.0.0:*:*:*:*:*:*:*
ibmleads9.1.0cpe:2.3:a:ibm:leads:9.1.0:*:*:*:*:*:*:*
ibmleads9.1.1cpe:2.3:a:ibm:leads:9.1.1:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.001

Percentile

29.8%

Related for NVD:CVE-2015-0127