CVE-2015-0145: XSS
Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0145?
CVE-2015-0145 has a medium severity rating due to its ability to allow unauthorized actions in the system.
How do I fix CVE-2015-0145?
To mitigate CVE-2015-0145, upgrade IBM OpenPages GRC Platform to the latest patched version as recommended by IBM.
What systems are affected by CVE-2015-0145?
CVE-2015-0145 affects IBM OpenPages GRC Platform versions 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1.
What type of vulnerability is CVE-2015-0145?
CVE-2015-0145 is classified as a cross-site request forgery (CSRF) vulnerability.
Who can exploit CVE-2015-0145?
CVE-2015-0145 can be exploited by remote authenticated users with the ability to hijack the authentication of other users.