CVE Database
/

CVE-2014-4816

Back to search

CVE-2014-4816

Published: Sep 23, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

VendorProductVersions

n/a

n/a

affected
n/a

References

69980
vdb-entry
x_refsource_BID
61423
third-party-advisory
x_refsource_SECUNIA
VU#573356
third-party-advisory
x_refsource_CERT-VN
61418
third-party-advisory
x_refsource_SECUNIA
PI23055
vendor-advisory
x_refsource_AIXAPAR

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now