CVE-2014-6077: XSS
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6077?
CVE-2014-6077 has a medium severity rating due to its potential for cross-site request forgery attacks.
How do I fix CVE-2014-6077?
To fix CVE-2014-6077, upgrade IBM Security Access Manager for Mobile to version 8.0.1 or later and for Web to version 7.0.0 FP10 or 8.0.1 or later.
What types of attacks can CVE-2014-6077 facilitate?
CVE-2014-6077 can facilitate remote cross-site request forgery attacks, potentially hijacking user sessions.
Which versions of IBM Security Access Manager are affected by CVE-2014-6077?
CVE-2014-6077 affects IBM Security Access Manager for Mobile versions before 8.0.1 and for Web versions before 7.0.0 FP10 and 8.0.1.
Is CVE-2014-6077 being actively exploited?
While there may have been instances of exploitation, the active status of CVE-2014-6077 should be monitored through security advisories.