First published: Sun Jan 03 2016(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Connections | <=3.0.1.1 | |
HCL Connections | =4.0 | |
HCL Connections | =4.5 | |
HCL Connections | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5037 has a Medium severity level due to its potential impact on user authentication.
To fix CVE-2015-5037, upgrade to IBM Connections version 3.0.1.1 CR3 or later for 3.x, and apply the updates for versions 4.0 CR4, 4.5 CR5, or 5.0 CR3.
CVE-2015-5037 affects users of IBM Connections versions prior to the specified fixes across multiple versions.
CVE-2015-5037 is a cross-site request forgery (CSRF) vulnerability.
The risks of CVE-2015-5037 include the possibility of remote authenticated users hijacking the authentication of other users.