CVE-2014-0864: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to hijack the authentication of arbitrary users for requests that change (1) a deal's currency or (2) a limit via a crafted XML document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0864?
CVE-2014-0864 has a medium severity rating due to its ability to allow CSRF attacks that can lead to unauthorized changes in user sessions.
How do I fix CVE-2014-0864?
To fix CVE-2014-0864, update IBM Algo Credit Limits to version 4.7.0.03 FP5 or later.
What applications are affected by CVE-2014-0864?
CVE-2014-0864 affects IBM Algo Credit Limits versions 4.5.0 through 4.7.0 prior to 4.7.0.03 FP5.
What types of actions can attackers perform using CVE-2014-0864?
Attackers can exploit CVE-2014-0864 to hijack user accounts and change deal currencies or other settings.
Is there a workaround for CVE-2014-0864 before applying the patch?
A potential workaround for CVE-2014-0864 is to implement CSRF tokens in forms to minimize the risk of unauthorized requests.