CVE-2014-6164

Publication date

2014-12-18 16:00:00

Family

ibm

State

PUBLISHED

Description

IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL.