Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-9517


There is an improper restriction of rendered UI layers or frames vulnerability in Micro Focus Service Manager Release Control versions 9.50 and 9.60. The vulnerability may result in the ability of malicious users to perform UI redress attacks.


Published

2020-03-09T16:15:16.077

Last Modified

2024-11-21T05:40:47.437

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-1021

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microfocus service_manager 9.50 Yes
Application microfocus service_manager 9.60 Yes

References