CVE-2014-3015 Information

Description

Cross-site request forgery (CSRF) vulnerability in the Web player in IBM Sametime Proxy Server and Web Client 9.0 through 9.0.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Reference

http://www-01.ibm.com/support/docview.wss?uid=swg21673260 https://exchange.xforce.ibmcloud.com/vulnerabilities/93026

Share on: