CVE-2014-0831: CSRF
Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configuration data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) 2.0 OACto a version that resolves this vulnerability.Fixed in 2.0.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0831?
CVE-2014-0831 is considered a high severity vulnerability due to its potential to allow unauthorized access to configuration data.
How do I fix CVE-2014-0831?
To fix CVE-2014-0831, upgrade IBM Financial Transaction Manager to version 2.0.0.3 or later.
What types of attacks are possible due to CVE-2014-0831?
CVE-2014-0831 allows attackers to perform cross-site request forgery (CSRF) attacks that can hijack user authentication.
Which versions of IBM Financial Transaction Manager are affected by CVE-2014-0831?
CVE-2014-0831 affects IBM Financial Transaction Manager versions 2.0.0.0 through 2.0.0.2.
Is user action required to exploit CVE-2014-0831?
Yes, exploitation of CVE-2014-0831 typically requires a user to be tricked into clicking a malicious link.