Vulnerability Name: | CVE-2014-0873 (CCN-90994) | ||||||||
Assigned: | 2014-03-06 | ||||||||
Published: | 2014-03-06 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM) Server 8.5 before 8.5.0.82, 9.0.1 before 9.0.1.38, 9.0.2 before 9.0.2.35, 10.0 before 10.0.0.0.26, and 10.1 before 10.1.0.0.15 allow remote attackers to hijack the authentication of arbitrary users. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-0873 Source: CCN Type: SA57337 IBM InfoSphere Master Data Management Cross-Site Request Forgery Vulnerability Source: CCN Type: IBM Security Bulletin 1666462 Cross-Site Request Forgery vulnerability in IBM InfoSphere Master Data Management Server (CVE-2014-0873) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21666462 Source: CCN Type: BID-66084 IBM InfoSphere Master Data Management Server CVE-2014-0873 Cross Site Request Forgery Vulnerability Source: XF Type: UNKNOWN ibm-infosphere-cve20140873-csrf(90994) Source: XF Type: UNKNOWN ibm-infosphere-cve20140873-csrf(90994) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |