CVE-2014-3024: CSRF
Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5.0.6 and Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk allows remote authenticated users to hijack the authentication of arbitrary users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3024?
CVE-2014-3024 is classified as a medium severity vulnerability due to its potential for CSRF attacks.
How do I fix CVE-2014-3024?
To fix CVE-2014-3024, users should apply the latest patches provided by IBM for affected versions of Maximo Asset Management and SmartCloud Control Desk.
Which versions of IBM Maximo Asset Management are affected by CVE-2014-3024?
CVE-2014-3024 affects IBM Maximo Asset Management versions 7.1 through 7.1.1.12 and 7.5 through 7.5.0.6.
Which versions of IBM SmartCloud Control Desk are impacted by CVE-2014-3024?
CVE-2014-3024 impacts IBM SmartCloud Control Desk versions 7.5.0 through 7.5.1.2.
What type of vulnerability is CVE-2014-3024?
CVE-2014-3024 is a Cross-Site Request Forgery (CSRF) vulnerability that allows authenticated users to hijack the authentication of others.