First published: Sat Feb 01 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configuration data.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | =2.0.0.0 | |
Ibm Financial Transaction Manager | =2.0.0.1 | |
Ibm Financial Transaction Manager | =2.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0831 is considered a high severity vulnerability due to its potential to allow unauthorized access to configuration data.
To fix CVE-2014-0831, upgrade IBM Financial Transaction Manager to version 2.0.0.3 or later.
CVE-2014-0831 allows attackers to perform cross-site request forgery (CSRF) attacks that can hijack user authentication.
CVE-2014-0831 affects IBM Financial Transaction Manager versions 2.0.0.0 through 2.0.0.2.
Yes, exploitation of CVE-2014-0831 typically requires a user to be tricked into clicking a malicious link.