Description
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38017 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser. |
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7176783 |
|
History
Fri, 10 Jan 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm engineering Lifecycle Optimization - Engineering Insights
|
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_engineering_insights:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:engineering_lifecycle_optimization_-_engineering_insights:7.0.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm engineering Lifecycle Optimization - Engineering Insights
|
Thu, 26 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Dec 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser. | |
| Title | IBM Engineering Lifecycle Optimization - Engineering Insights tabnabbing | |
| First Time appeared |
Ibm
Ibm engineering Insights |
|
| Weaknesses | CWE-1022 | |
| CPEs | cpe:2.3:a:ibm:engineering_insights:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:engineering_insights:7.0.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm engineering Insights |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-12-26T18:11:41.366Z
Reserved: 2024-06-28T09:34:20.322Z
Link: CVE-2024-39727
Updated: 2024-12-26T18:11:37.669Z
Status : Analyzed
Published: 2024-12-25T14:15:22.610
Modified: 2025-01-10T20:15:39.980
Link: CVE-2024-39727
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD