IBM Security Identity Manager CVE-2014-6105 Clickjacking Vulnerability
BID:71116
Info
IBM Security Identity Manager CVE-2014-6105 Clickjacking Vulnerability
| Bugtraq ID: | 71116 |
| Class: | Design Error |
| CVE: |
CVE-2014-6105 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2014 12:00AM |
| Updated: | Nov 13 2014 12:00AM |
| Credit: | IBM Security Systems Ethical Hacking Team: Paul Ionescu, Brennan Brazeau, John Zuccato, Jonathan Fitz-Gerald, and Warren Moynihan. |
| Vulnerable: |
IBM Security Identity Manager 6.0.0 |
| Not Vulnerable: | |
Discussion
IBM Security Identity Manager CVE-2014-6105 Clickjacking Vulnerability
IBM Security Identity Manager is prone to a clickjacking vulnerability.
Successful exploits will allow an attacker to compromise the affected application or obtain sensitive information. Other attacks are also possible.
IBM Security Identity Manager is prone to a clickjacking vulnerability.
Successful exploits will allow an attacker to compromise the affected application or obtain sensitive information. Other attacks are also possible.
Exploit / POC
IBM Security Identity Manager CVE-2014-6105 Clickjacking Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to visit a crafted webpage.
An attacker can exploit this issue by enticing an unsuspecting user to visit a crafted webpage.
References
IBM Security Identity Manager CVE-2014-6105 Clickjacking Vulnerability
References:
References: