Vulnerability Name: CVE-2014-6106 (CCN-96145) Assigned: 2014-09-02 Published: 2015-03-02 Updated: 2017-09-22 Summary: Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors. CVSS v3 Severity: 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-352 Vulnerability Consequences: Cross-Site Scripting References: Source: MITRE Type: CNACVE-2014-6106 Source: CCN Type: IBM Security Bulletin 1698020Multiple Vulnerabilities fixed in IBM Security Identity Manager Virtual Appliance ( CVE-2014-6106, CVE-2014-6108, CVE-2014-6109, CVE-2014-6111, CVE-2014-6112 ) Source: BID Type: Third Party Advisory, VDB Entry73167 Source: CCN Type: BID-73167IBM Security Identity Manager CVE-2014-6106 Cross Site Request Forgery Vulnerability Source: XF Type: UNKNOWNibm-sim-cve20146106-csrf(96145) Source: XF Type: Vendor Advisoryibm-sim-cve20146106-csrf(96145) Source: CONFIRM Type: Patch, Vendor Advisoryhttps://www-01.ibm.com/support/docview.wss?uid=swg21698020 Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:security_identity_manager:5.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.8:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.9:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.10:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.11:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.12:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.13:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.14:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0.15:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:6.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:6.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:6.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:6.0.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:6.0.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:7.0.0.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:ibm:security_identity_manager:6.0:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:5.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:security_identity_manager:7.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
ibm security identity manager 5.1.0
ibm security identity manager 5.1.0.3
ibm security identity manager 5.1.0.4
ibm security identity manager 5.1.0.5
ibm security identity manager 5.1.0.6
ibm security identity manager 5.1.0.7
ibm security identity manager 5.1.0.8
ibm security identity manager 5.1.0.9
ibm security identity manager 5.1.0.10
ibm security identity manager 5.1.0.11
ibm security identity manager 5.1.0.12
ibm security identity manager 5.1.0.13
ibm security identity manager 5.1.0.14
ibm security identity manager 5.1.0.15
ibm security identity manager 6.0.0.0
ibm security identity manager 6.0.0.1
ibm security identity manager 6.0.0.2
ibm security identity manager 6.0.0.3
ibm security identity manager 6.0.0.4
ibm security identity manager 7.0.0.0
ibm security identity manager 6.0
ibm security identity manager 5.1.0
ibm security identity manager 7.0