Cross-Site Request Forgery Vulnerability in IBM Identity Manager Products
CVE-2014-0961

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
8 June 2014

Summary

This vulnerability allows remote authenticated users to exploit weak session management in IBM Tivoli Identity Manager and IBM Security Identity Manager. By leveraging CSRF techniques, attackers can hijack the authentication of arbitrary users, potentially using malicious requests that insert cross-site scripting (XSS) payloads. This can lead to unauthorized actions being performed on behalf of legitimate users, significantly compromising security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.