CVE-2014-6125: XSS
Published Oct 28, 2014
·Updated
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected Software
1 affected component
IBM WebSphere Portal=8.5.0.0
Remediation
Patch Available
Event History
Oct 28, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6125?
The severity of CVE-2014-6125 is rated as medium due to its potential for exploitation through cross-site request forgery.
2
How do I fix CVE-2014-6125?
To fix CVE-2014-6125, upgrade to IBM WebSphere Portal version 8.5.0.0 with the appropriate fix pack installed.
3
What kind of attacks can originate from CVE-2014-6125?
CVE-2014-6125 allows attackers to perform cross-site request forgery attacks which can lead to the hijacking of user sessions.
4
Which versions of IBM WebSphere Portal are affected by CVE-2014-6125?
CVE-2014-6125 affects IBM WebSphere Portal version 8.5.0 before CF03.
5
Is user authentication at risk due to CVE-2014-6125?
Yes, user authentication can be hijacked by exploiting CVE-2014-6125, compromising user security.