3.5
CVSSv2

CVE-2020-4406

Published: 15/06/2020 Updated: 18/06/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

IBM Spectrum Protect Client 8.1.7.0 up to and including 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 up to and including 8.1.9.1 (Linux), 8.1.9.0 up to and including 8.1.9.1 (AIX) web user interfaces could allow a remote malicious user to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 179488.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm spectrum_protect_client

ibm spectrum_protect_for_space_management