CVE-2014-0961
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication…
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- ibm/security identity manager · ibm/tivoli identity manager
- Source
- psirt@us.ibm.com
References
- http://secunia.com/advisories/59080
- http://www-01.ibm.com/support/docview.wss?uid=swg21674754Vendor Advisory
- http://www.securityfocus.com/bid/67909
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92747
- http://secunia.com/advisories/59080
- http://www-01.ibm.com/support/docview.wss?uid=swg21674754Vendor Advisory
- http://www.securityfocus.com/bid/67909
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92747
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.