CVE-2014-6090
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix10, and 6.0.5 before 6.0.5.6 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Múltiples vulnerabilidades de CSRF en los servlets (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, y (3) IEGEditorCommands en IBM Curam Social Program Management (SPM) 5.2 SP6 anterior a EP6, 6.0 SP2 anterior a EP26, 6.0.3 anterior a 6.0.3.0 iFix8, 6.0.4 anterior a 6.0.4.5 iFix10, y 6.0.5 anterior a 6.0.5.6 permiten a atacantes remotos secuestrar la autenticación de usuarios arbitrarios para solicitudes que insertan secuencias de XSS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-09-02 CVE Reserved
- 2015-04-27 CVE Published
- 2023-08-30 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21697726 | 2015-04-27 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Curam Social Program Management Search vendor "Ibm" for product "Curam Social Program Management" | 5.2 Search vendor "Ibm" for product "Curam Social Program Management" and version "5.2" | sp6 |
Affected
| ||||||
Ibm Search vendor "Ibm" | Curam Social Program Management Search vendor "Ibm" for product "Curam Social Program Management" | 6.0 Search vendor "Ibm" for product "Curam Social Program Management" and version "6.0" | sp2 |
Affected
| ||||||
Ibm Search vendor "Ibm" | Curam Social Program Management Search vendor "Ibm" for product "Curam Social Program Management" | 6.0.3.0 Search vendor "Ibm" for product "Curam Social Program Management" and version "6.0.3.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Curam Social Program Management Search vendor "Ibm" for product "Curam Social Program Management" | 6.0.4.0 Search vendor "Ibm" for product "Curam Social Program Management" and version "6.0.4.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Curam Social Program Management Search vendor "Ibm" for product "Curam Social Program Management" | 6.0.5.0 Search vendor "Ibm" for product "Curam Social Program Management" and version "6.0.5.0" | - |
Affected
|