VYPR
Medium severity5.4NVD Advisory· Published Feb 24, 2022· Updated Jun 17, 2026

CVE-2021-39038

CVE-2021-39038

Description

IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 213968.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*range: >=9.0.0.0,<9.0.5.12
    • cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*range: >=17.0.0.3,<=22.0.0.2
    • (no CPE)range: 9.0
    • (no CPE)range: 9.0
    • (no CPE)range: 17.0.0.3
  • Range: 17.0.0.3 - 22.0.0.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.