CSRF Vulnerability in IBM Emptoris Spend Analysis Products
CVE-2014-3061
Currently unrated
Summary
A cross-site request forgery (CSRF) vulnerability exists in IBM Emptoris Spend Analysis, allowing attackers to potentially hijack user authentication. Specifically, this flaw enables unauthorized users to craft requests that can insert cross-site scripting (XSS) sequences, compromising the integrity of user sessions and leading to unauthorized actions on behalf of legitimate users. This vulnerability affects several versions of the software, underscoring the importance of updating to the latest releases to mitigate potential risks.
References
Timeline
Vulnerability published
Vulnerability Reserved