CVE-2020-4406
Last modified
CVE-2020-4406 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. EPSS estimates a 0.82% chance of exploitation in the next 30 days.
Description
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Spectrum Protect Client | >= 8.1.7.0, <= 8.1.9.1 |
| Ibm | Spectrum Protect Client | >= 8.1.9.0, <= 8.1.9.1 |
| Ibm | Spectrum Protect For Space Management | >= 8.1.7.0, <= 8.1.9.1 |
| Ibm | Spectrum Protect For Space Management | >= 8.1.9.0, <= 8.1.9.1 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/179488VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6221448Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/179488VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6221448Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-4406?
How severe is CVE-2020-4406?
How do I fix CVE-2020-4406?
Are you affected by CVE-2020-4406?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
