IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
The web application produces links to untrusted external sites outside of its sphere of control, but it does not properly prevent the external site from modifying security-critical properties of the window.opener object, such as the location property.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Engineering_lifecycle_optimization_-_engineering_insights | Ibm | 7.0.2 (including) | 7.0.2 (including) |
Engineering_lifecycle_optimization_-_engineering_insights | Ibm | 7.0.3 (including) | 7.0.3 (including) |