Vulnerability Name: | CVE-2015-0115 (CCN-99978) |
Assigned: | 2014-11-18 |
Published: | 2015-06-19 |
Updated: | 2015-06-29 |
Summary: | Cross-site request forgery (CSRF) vulnerability in IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 allows remote authenticated users to hijack the authentication of customer accounts.
|
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): High Privileges Required (PR): Low User Interaction (UI): Required | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 5.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 3.5 Low (CCN CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-352
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2015-0115
Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21902807
Source: CCN Type: IBM Security Bulletin 1902807 Multiple vulnerabilities in IBM Leads (CVE-2015-0127, CVE-2015-0126, CVE-2015-0115, CVE-2015-0131, CVE-2015-0116)
Source: XF Type: UNKNOWN ibm-leads-cve20150115-csrf(99978)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:ibm:leads:7.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:7.1.1:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:7.5.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:8.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:8.2.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:8.5.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:8.6.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:9.0.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:9.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:9.1.1:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:ibm:leads:8.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:8.2.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:8.5.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:8.6.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:9.0.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:9.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:leads:9.1.1:*:*:*:*:*:*:* Denotes that component is vulnerable |
BACK |