![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2014-4816 |
Description: | Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-4816 AIX APAR: PI23055 http://www-01.ibm.com/support/docview.wss?uid=swg1PI23055 BugTraq ID: 69980 http://www.securityfocus.com/bid/69980 CERT/CC vulnerability note: VU#573356 http://www.kb.cert.org/vuls/id/573356 http://secunia.com/advisories/61418 http://secunia.com/advisories/61423 XForce ISS Database: ibm-websphere-cve20144816-csrf(95402) https://exchange.xforce.ibmcloud.com/vulnerabilities/95402 |