CVE-2024-39727
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS probability
- 0.35%
- CWE
- CWE-1022
- Published
- 2024-12-25
- Last modified
- 2026-03-13
Affected products
- IBM Engineering Insights
Weakness type
Related vulnerabilities
- CVE-2026-71555 — PILOS: Reverse tabnabbing in room description
- CVE-2025-59842 — JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
- CVE-2025-42941 — Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)
- CVE-2025-33014 — IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection
- CVE-2018-25089 — glb Meetup Tag Extension Link Attribute reverse tabnabbing
- CVE-2022-4927 — ualbertalib NEOSDiscovery _refworks.html.erb reverse tabnabbing
- CVE-2018-25058 — Twitter-Post-Fetcher Link Target twitterFetcher.js reverse tabnabbing
- CVE-2020-36624 — ahorner text-helpers translation.rb reverse tabnabbing