CVE-2014-4816 Information

Description

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47 7.0 before 7.0.0.35 8.0 before 8.0.0.10 and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Reference

http://secunia.com/advisories/61418 http://secunia.com/advisories/61423 http://www.kb.cert.org/vuls/id/573356 http://www.securityfocus.com/bid/69980 http://www-01.ibm.com/support/docview.wss?uid=swg1PI23055 http://www-01.ibm.com/support/docview.wss?uid=swg21682767 https://exchange.xforce.ibmcloud.com/vulnerabilities/95402

Share on: