CVE-2014-3037: XSS
Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager before 4.0.7 and 5.x before 5.0.1, Rational Software Architect Design Manager before 4.0.7 and 5.x before 5.0.1, and Rational Rhapsody Design Manager before 4.0.7 and 5.x before 5.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3037?
The severity of CVE-2014-3037 is considered high due to its potential for cross-site request forgery.
How do I fix CVE-2014-3037?
To fix CVE-2014-3037, upgrade to IBM Rational Engineering Lifecycle Manager version 4.0.7 or later, Rational Software Architect Design Manager version 4.0.7 or later, or Rational Rhapsody Design Manager version 4.0.7 or later.
What applications are affected by CVE-2014-3037?
CVE-2014-3037 affects IBM Rational Engineering Lifecycle Manager, Rational Software Architect Design Manager, and Rational Rhapsody Design Manager, particularly versions prior to 4.0.7.
What type of vulnerability is CVE-2014-3037?
CVE-2014-3037 is a cross-site request forgery (CSRF) vulnerability that can allow an attacker to perform unauthorized actions on behalf of an authenticated user.
Is CVE-2014-3037 exploitable remotely?
Yes, CVE-2014-3037 is exploitable remotely, which increases the risk associated with this vulnerability.