First published: Tue Aug 26 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Spend Analysis | =9.5.0.0 | |
IBM Emptoris Spend Analysis | =9.5.0.1 | |
IBM Emptoris Spend Analysis | =9.5.0.2 | |
IBM Emptoris Spend Analysis | =9.5.0.3 | |
IBM Emptoris Spend Analysis | =10.0.1.0 | |
IBM Emptoris Spend Analysis | =10.0.1.1 | |
IBM Emptoris Spend Analysis | =10.0.1.2 | |
IBM Emptoris Spend Analysis | =10.0.2.0 | |
IBM Emptoris Spend Analysis | =10.0.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3061 has a medium severity rating due to its potential for unauthorized actions due to CSRF exploitation.
To fix CVE-2014-3061, upgrade IBM Emptoris Spend Analysis to version 9.5.0.4, 10.0.1.3, or 10.0.2.4 or later.
CVE-2014-3061 allows attackers to perform Cross-site Request Forgery (CSRF) attacks that can hijack user sessions.
IBM Emptoris Spend Analysis versions 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 are affected by CVE-2014-3061.
CVE-2014-3061 can lead to unauthorized actions by hijacking user authentication, compromising user security.