CVE-2014-0969: CSRF
Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary users.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0969?
CVE-2014-0969 is classified as a medium severity vulnerability due to the potential for cross-site request forgery.
How do I fix CVE-2014-0969?
To mitigate CVE-2014-0969, upgrade to IBM InfoSphere Master Data Management versions 11.0-FP5 or higher, or 11.3-IF2 and above.
Which IBM InfoSphere products are affected by CVE-2014-0969?
CVE-2014-0969 affects IBM InfoSphere Master Data Management - Collaborative Edition versions 10.x and 11.x prior to 11.0-FP5, as well as InfoSphere Master Data Management Server for Product Information Management versions 9.x through 11.x before 11.3-IF2.
Is CVE-2014-0969 a remote attack vector?
Yes, CVE-2014-0969 allows remote authenticated attackers to perform actions on behalf of users due to the CSRF nature of the vulnerability.
What mitigation strategies can be employed for CVE-2014-0969?
In addition to upgrading, users can implement CSRF tokens and validate requests to mitigate potential risks associated with CVE-2014-0969.