4.3
CVSSv2

CVE-2014-4778

Published: 25/05/2015 Updated: 26/05/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

IBM License Metric Tool 9 prior to 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 prior to 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote malicious users to conduct clickjacking attacks via vectors involving a FRAME element.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm endpoint manager family 9.0.1

ibm license metric tool 9.0

ibm license metric tool 9.0.1

ibm license metric tool 9.1.0.1

ibm endpoint manager family 9.1.0