Cross-Site Request Forgery Vulnerability in IBM License Metric Tool and Endpoint Manager
CVE-2014-4774

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
25 May 2015

Summary

A Cross-site request forgery vulnerability exists in the login interface of IBM License Metric Tool and Endpoint Manager for Software Use Analysis, prior to version 9.1.0.2. This flaw enables remote attackers to exploit the authentication process, potentially allowing unauthorized access by leveraging the FRAME element in the request. Users need to be aware of this security issue to safeguard their accounts and systems from potential attacks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.