CSRF Vulnerability in IBM Emptoris Spend Analysis Products
CVE-2014-3061

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 August 2014

Summary

A cross-site request forgery (CSRF) vulnerability exists in IBM Emptoris Spend Analysis, allowing attackers to potentially hijack user authentication. Specifically, this flaw enables unauthorized users to craft requests that can insert cross-site scripting (XSS) sequences, compromising the integrity of user sessions and leading to unauthorized actions on behalf of legitimate users. This vulnerability affects several versions of the software, underscoring the importance of updating to the latest releases to mitigate potential risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.