CVE Vulnerabilities

CVE-2015-0127

Published: Jun 28, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.

Affected Software

NameVendorStart VersionEnd Version
LeadsIbm7.1.0 (including)7.1.0 (including)
LeadsIbm7.1.1 (including)7.1.1 (including)
LeadsIbm7.5.0 (including)7.5.0 (including)
LeadsIbm8.1.0 (including)8.1.0 (including)
LeadsIbm8.2.0 (including)8.2.0 (including)
LeadsIbm8.5.0 (including)8.5.0 (including)
LeadsIbm8.6.0 (including)8.6.0 (including)
LeadsIbm9.0.0 (including)9.0.0 (including)
LeadsIbm9.1.0 (including)9.1.0 (including)
LeadsIbm9.1.1 (including)9.1.1 (including)

References