First published: Fri May 16 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hijack the authentication of arbitrary users.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Metadata Workbench | =8.1.0 | |
IBM InfoSphere Metadata Workbench | =8.1.0.1 | |
IBM InfoSphere Metadata Workbench | =8.1.0.2 | |
IBM InfoSphere Metadata Workbench | =8.1.1 | |
IBM InfoSphere Metadata Workbench | =8.5.0 | |
IBM InfoSphere Metadata Workbench | =8.5.0.1 | |
IBM InfoSphere Metadata Workbench | =8.5.0.2 | |
IBM InfoSphere Metadata Workbench | =8.5.0.3 | |
IBM InfoSphere Metadata Workbench | =8.7.0 | |
IBM InfoSphere Metadata Workbench | =8.7.0.1 | |
IBM InfoSphere Metadata Workbench | =8.7.0.2 | |
IBM InfoSphere Metadata Workbench | =9.1.0 | |
IBM InfoSphere Metadata Workbench | =9.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-0933 is classified as Medium due to the potential for unauthorized access to sensitive user actions.
To fix CVE-2014-0933, apply the latest security patches recommended by IBM for affected versions of InfoSphere Information Server Metadata Workbench.
CVE-2014-0933 affects users of IBM InfoSphere Information Server Metadata Workbench versions 8.1 through 9.1.
CVE-2014-0933 is a Cross-Site Request Forgery (CSRF) vulnerability, allowing attackers to impersonate users.
The impact of CVE-2014-0933 includes potential hijacking of user authentication, leading to unauthorized actions on behalf of the user.