First published: Wed Sep 10 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager before 4.0.7 and 5.x before 5.0.1, Rational Software Architect Design Manager before 4.0.7 and 5.x before 5.0.1, and Rational Rhapsody Design Manager before 4.0.7 and 5.x before 5.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rhapsody Design Manager | <=4.0.6 | |
IBM Rhapsody Design Manager | =3.0 | |
IBM Rhapsody Design Manager | =3.0.0.1 | |
IBM Rhapsody Design Manager | =3.0.1 | |
IBM Rhapsody Design Manager | =4.0 | |
IBM Rhapsody Design Manager | =4.0.1 | |
IBM Rhapsody Design Manager | =4.0.2 | |
IBM Rhapsody Design Manager | =4.0.3 | |
IBM Rhapsody Design Manager | =4.0.4 | |
IBM Rhapsody Design Manager | =4.0.5 | |
IBM Rhapsody Design Manager | =5.0 | |
IBM Engineering Lifecycle Manager | <=4.06 | |
IBM Engineering Lifecycle Manager | =1.0 | |
IBM Engineering Lifecycle Manager | =1.0.0.1 | |
IBM Engineering Lifecycle Manager | =4.03 | |
IBM Engineering Lifecycle Manager | =4.04 | |
IBM Engineering Lifecycle Manager | =4.05 | |
IBM Engineering Lifecycle Manager | =5.0 | |
IBM Rational Software Architect Design Manager | <=4.0.6 | |
IBM Rational Software Architect Design Manager | =3.0 | |
IBM Rational Software Architect Design Manager | =3.0.0.1 | |
IBM Rational Software Architect Design Manager | =4.0.0 | |
IBM Rational Software Architect Design Manager | =4.0.1 | |
IBM Rational Software Architect Design Manager | =4.0.2 | |
IBM Rational Software Architect Design Manager | =4.0.3 | |
IBM Rational Software Architect Design Manager | =4.0.4 | |
IBM Rational Software Architect Design Manager | =4.0.5 | |
IBM Rational Software Architect Design Manager | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3037 is considered high due to its potential for cross-site request forgery.
To fix CVE-2014-3037, upgrade to IBM Rational Engineering Lifecycle Manager version 4.0.7 or later, Rational Software Architect Design Manager version 4.0.7 or later, or Rational Rhapsody Design Manager version 4.0.7 or later.
CVE-2014-3037 affects IBM Rational Engineering Lifecycle Manager, Rational Software Architect Design Manager, and Rational Rhapsody Design Manager, particularly versions prior to 4.0.7.
CVE-2014-3037 is a cross-site request forgery (CSRF) vulnerability that can allow an attacker to perform unauthorized actions on behalf of an authenticated user.
Yes, CVE-2014-3037 is exploitable remotely, which increases the risk associated with this vulnerability.