Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix10, and 6.0.5 before 6.0.5.6 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21697726 | Patch Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21697726 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:13
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21697726 - Patch, Vendor Advisory |
Information
Published : 2015-04-27 11:59
Updated : 2024-11-21 02:13
NVD link : CVE-2014-6090
Mitre link : CVE-2014-6090
CVE.ORG link : CVE-2014-6090
JSON object : View
Products Affected
ibm
- curam_social_program_management
CWE
CWE-352
Cross-Site Request Forgery (CSRF)