First published: Thu Dec 11 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Datapower Xc10 Appliance Firmware | =2.1.0.0 | |
Ibm Websphere Datapower Xc10 Appliance Firmware | =2.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3058 is considered medium due to the potential for user authentication hijacking.
To fix CVE-2014-3058, upgrade the IBM WebSphere DataPower XC10 appliance to version 2.1 FP4 or later, or version 2.5 FP4 or later.
CVE-2014-3058 affects users of the IBM WebSphere DataPower XC10 appliance on firmware versions 2.1.0.0 and 2.5.0.0 before FP4.
CVE-2014-3058 is a cross-site request forgery (CSRF) vulnerability that allows remote authenticated users to hijack authentication.
Yes, CVE-2014-3058 can allow XSS sequences to be inserted into requests, potentially leading to further security issues.