Vulnerability Name: | CVE-2014-0929 (CCN-92261) | ||||||||
Assigned: | 2014-06-04 | ||||||||
Published: | 2014-06-04 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that trigger follow actions. | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 5.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-0929 Source: SECUNIA Type: UNKNOWN 59046 Source: AIXAPAR Type: UNKNOWN LO79622 Source: CCN Type: IBM Security Bulletin 1668509 IBM Connections Security Update (CVE-2014-0929) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21668509 Source: CCN Type: BID-67987 IBM Connections Profiles Component Unspecified Cross-Site Request Forgery Vulnerability Source: XF Type: UNKNOWN ibm-connections-cve20140929-csrf(92261) Source: XF Type: UNKNOWN ibm-connections-cve20140929-csrf(92261) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |