Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-869p-rj24-pjcc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.

IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.

EPSS

Процентиль: 44%
0.00218
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 10 лет назад

IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.

EPSS

Процентиль: 44%
0.00218
Низкий

Дефекты

CWE-20