IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks via a crafted web site.
                
            References
                    | Link | Resource | 
|---|---|
| http://www-01.ibm.com/support/docview.wss?uid=swg21902807 | Vendor Advisory | 
| http://www-01.ibm.com/support/docview.wss?uid=swg21902807 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 02:22
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www-01.ibm.com/support/docview.wss?uid=swg21902807 - Vendor Advisory | 
Information
                Published : 2015-06-28 22:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-0127
Mitre link : CVE-2015-0127
CVE.ORG link : CVE-2015-0127
JSON object : View
Products Affected
                ibm
- leads
 
CWE
                
                    
                        
                        CWE-254
                        
            7PK - Security Features
