CVE-2014-4785 Information

Description

Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013 9.7 before 9.7.093013 10.0 before 10.0.093013 and 10.1 before 10.1.093013 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Reference

http://secunia.com/advisories/60996 http://www.securityfocus.com/bid/69694 http://www-01.ibm.com/support/docview.wss?uid=swg21682450 https://exchange.xforce.ibmcloud.com/vulnerabilities/95032

Share on: