VulnerabilityModified
CVE-2014-3061
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert…
MEDIUM 6.8EPSS 0.63%
Does this matter?
Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- ibm/emptoris spend analysis
- Source
- psirt@us.ibm.com
References
- http://secunia.com/advisories/60480
- http://www-01.ibm.com/support/docview.wss?uid=swg21681277Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93537
- http://secunia.com/advisories/60480
- http://www-01.ibm.com/support/docview.wss?uid=swg21681277Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93537
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.