Security Advisory

CVE-2014-6077

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2014-12-18 16:00:00
Last updated 2024-08-06 12:03:02
Assigner ibm
State PUBLISHED

Description

Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.