CVE-2014-6187: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x before 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6187?
CVE-2014-6187 is classified as a moderate severity vulnerability.
How do I fix CVE-2014-6187?
To fix CVE-2014-6187, upgrade your IBM WebSphere Service Registry and Repository to the latest versions mentioned in the vulnerability report.
Which versions are affected by CVE-2014-6187?
CVE-2014-6187 affects IBM WebSphere Service Registry and Repository versions 6.3.x before 6.3.0.5, 7.0.x before 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2.
What types of attacks can CVE-2014-6187 enable?
CVE-2014-6187 can enable cross-site request forgery (CSRF) attacks, potentially allowing attackers to hijack authentication sessions of users.
Is there a patch available for CVE-2014-6187?
Yes, a patch is available as part of the upgrades for the affected versions of IBM WebSphere Service Registry and Repository.