Description
IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.
Affected products
- IBM Corporation / InfoSphere Information Server8.1 – 8.1
- IBM Corporation / InfoSphere Information Server8.5 – 8.5
- IBM Corporation / InfoSphere Information Server8.0 – 8.0
- IBM Corporation / InfoSphere Information Server8.5.0.1 – 8.5.0.1
- IBM Corporation / InfoSphere Information Server8.7 – 8.7
- IBM Corporation / InfoSphere Information Server9.1 – 9.1
- IBM Corporation / InfoSphere Information Server8.0.1 – 8.0.1
- IBM Corporation / InfoSphere Information Server10.0 – 10.0
- IBM Corporation / InfoSphere Information Server11.3 – 11.3
- IBM Corporation / InfoSphere Information Server10 – 10
- IBM Corporation / InfoSphere Information Server11.3.0.0 – 11.3.0.0
- IBM Corporation / InfoSphere Information Server11.3.1.0 – 11.3.1.0
- IBM Corporation / InfoSphere Information Server11.5 – 11.5