Cross-Site Request Forgery Vulnerability in IBM Identity Manager Products
CVE-2014-0961
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 8 June 2014
Summary
This vulnerability allows remote authenticated users to exploit weak session management in IBM Tivoli Identity Manager and IBM Security Identity Manager. By leveraging CSRF techniques, attackers can hijack the authentication of arbitrary users, potentially using malicious requests that insert cross-site scripting (XSS) payloads. This can lead to unauthorized actions being performed on behalf of legitimate users, significantly compromising security.
References
Timeline
Vulnerability published
Vulnerability Reserved