IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Leads | Ibm | 7.1.0 (including) | 7.1.0 (including) |
Leads | Ibm | 7.1.1 (including) | 7.1.1 (including) |
Leads | Ibm | 7.5.0 (including) | 7.5.0 (including) |
Leads | Ibm | 8.1.0 (including) | 8.1.0 (including) |
Leads | Ibm | 8.2.0 (including) | 8.2.0 (including) |
Leads | Ibm | 8.5.0 (including) | 8.5.0 (including) |
Leads | Ibm | 8.6.0 (including) | 8.6.0 (including) |
Leads | Ibm | 9.0.0 (including) | 9.0.0 (including) |
Leads | Ibm | 9.1.0 (including) | 9.1.0 (including) |
Leads | Ibm | 9.1.1 (including) | 9.1.1 (including) |