CVE-2014-0961: XSS
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0961?
CVE-2014-0961 has been classified as a medium severity vulnerability due to its potential impact on user authentication.
How do I fix CVE-2014-0961?
To fix CVE-2014-0961, you should apply the latest patches provided by IBM for affected versions of IBM Tivoli Identity Manager and IBM Security Identity Manager.
Which versions are affected by CVE-2014-0961?
CVE-2014-0961 affects IBM Tivoli Identity Manager versions before 5.0.0.15 and 5.1.0.15, and IBM Security Identity Manager versions before 6.0.0.2.
What type of vulnerability is CVE-2014-0961?
CVE-2014-0961 is a Cross-site Request Forgery (CSRF) vulnerability that allows remote authenticated users to hijack the authentication of other users.
What are the consequences of CVE-2014-0961?
If exploited, CVE-2014-0961 can lead to unauthorized actions taken in the context of an authenticated user, potentially compromising sensitive data.