CVE-2014-3009Improper Input Validation in IBM Infosphere Master Data Management

Severity
3.5LOWNVD
EPSS
0.1%
top 66.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateMay 17

Description

The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-g9c7-hw42-vp3f: The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 102022-05-17
CVEList
CVE-2014-3009: The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 102014-08-01
CVE-2014-3009 — Improper Input Validation in IBM | cvebase