CVE-2024-30109

HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended.
Configurations

No configuration.

History

21 Nov 2024, 09:11

Type Values Removed Values Added
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0114193 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0114193 -
Summary
  • (es) HCL DRYiCE AEX se ve afectado por la falta de protección contra el clickjacking en la aplicación web AEX. Un atacante puede utilizar múltiples capas transparentes u opacas para engañar a un usuario para que haga clic en un botón o enlace en una página distinta a la prevista.

28 Jun 2024, 10:27

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-28 06:15

Updated : 2024-11-21 09:11


NVD link : CVE-2024-30109

Mitre link : CVE-2024-30109

CVE.ORG link : CVE-2024-30109


JSON object : View

Products Affected

No product.

CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames