IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web site.
https://exchange.xforce.ibmcloud.com/vulnerabilities/98486
https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-6060