First published: Sat Oct 03 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages | =6.2.0.0 | |
IBM OpenPages | =6.2.1.0 | |
IBM OpenPages | =6.2.1.1 | |
IBM OpenPages | =7.0.0.0 | |
IBM OpenPages | =7.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0145 has a medium severity rating due to its ability to allow unauthorized actions in the system.
To mitigate CVE-2015-0145, upgrade IBM OpenPages GRC Platform to the latest patched version as recommended by IBM.
CVE-2015-0145 affects IBM OpenPages GRC Platform versions 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1.
CVE-2015-0145 is classified as a cross-site request forgery (CSRF) vulnerability.
CVE-2015-0145 can be exploited by remote authenticated users with the ability to hijack the authentication of other users.