First published: Wed Dec 24 2014(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x before 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Service Registry and Repository | =6.3.0 | |
IBM WebSphere Service Registry and Repository | =6.3.0.1 | |
IBM WebSphere Service Registry and Repository | =6.3.0.2 | |
IBM WebSphere Service Registry and Repository | =6.3.0.3 | |
IBM WebSphere Service Registry and Repository | =6.3.0.4 | |
IBM WebSphere Service Registry and Repository | =7.0.0 | |
IBM WebSphere Service Registry and Repository | =7.0.0.1 | |
IBM WebSphere Service Registry and Repository | =7.0.0.2 | |
IBM WebSphere Service Registry and Repository | =7.0.0.3 | |
IBM WebSphere Service Registry and Repository | =7.0.0.4 | |
IBM WebSphere Service Registry and Repository | =7.5.0.0 | |
IBM WebSphere Service Registry and Repository | =7.5.0.1 | |
IBM WebSphere Service Registry and Repository | =7.5.0.2 | |
IBM WebSphere Service Registry and Repository | =8.0 | |
IBM WebSphere Service Registry and Repository | =8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6187 is classified as a moderate severity vulnerability.
To fix CVE-2014-6187, upgrade your IBM WebSphere Service Registry and Repository to the latest versions mentioned in the vulnerability report.
CVE-2014-6187 affects IBM WebSphere Service Registry and Repository versions 6.3.x before 6.3.0.5, 7.0.x before 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2.
CVE-2014-6187 can enable cross-site request forgery (CSRF) attacks, potentially allowing attackers to hijack authentication sessions of users.
Yes, a patch is available as part of the upgrades for the affected versions of IBM WebSphere Service Registry and Repository.