First published: Wed Oct 29 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM TRIRIGA Application Platform | =3.2 | |
IBM TRIRIGA Application Platform | =3.3.0.0 | |
IBM TRIRIGA Application Platform | =3.3.0.1 | |
IBM TRIRIGA Application Platform | =3.3.1.1 | |
IBM TRIRIGA Application Platform | =3.3.1.2 | |
IBM TRIRIGA Application Platform | =3.3.2.0 | |
IBM TRIRIGA Application Platform | =3.3.2.1 | |
IBM TRIRIGA Application Platform | =3.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4839 has a medium severity rating due to its ability to facilitate cross-site request forgery attacks.
To fix CVE-2014-4839, upgrade IBM TRIRIGA Application Platform to versions 3.3.0.2, 3.3.1.3, 3.3.2.2, or 3.4.0.1 or later.
CVE-2014-4839 affects users of IBM TRIRIGA Application Platform versions 3.2, 3.3.0.0, 3.3.1.1, 3.3.1.2, 3.3.2.0, and 3.4.0.0.
CVE-2014-4839 is classified as a cross-site request forgery (CSRF) vulnerability.
CVE-2014-4839 can be exploited by authenticated users, potentially allowing them to hijack other users' authenticated sessions.