CVE-2014-3061 Information

Description

Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4 10.0.1.x before 10.0.1.3 and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Reference

http://secunia.com/advisories/60480 http://www-01.ibm.com/support/docview.wss?uid=swg21681277 https://exchange.xforce.ibmcloud.com/vulnerabilities/93537

Share on: