6
CVE-2014-6187
- EPSS 0.87%
- Veröffentlicht 24.12.2014 11:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x before 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Service Registry And Repository Version 6.3.0
Ibm ≫ Websphere Service Registry And Repository Version 6.3.0.1
Ibm ≫ Websphere Service Registry And Repository Version 6.3.0.2
Ibm ≫ Websphere Service Registry And Repository Version 6.3.0.3
Ibm ≫ Websphere Service Registry And Repository Version 6.3.0.4
Ibm ≫ Websphere Service Registry And Repository Version 7.0.0
Ibm ≫ Websphere Service Registry And Repository Version 7.0.0.1
Ibm ≫ Websphere Service Registry And Repository Version 7.0.0.2
Ibm ≫ Websphere Service Registry And Repository Version 7.0.0.3
Ibm ≫ Websphere Service Registry And Repository Version 7.0.0.4
Ibm ≫ Websphere Service Registry And Repository Version 7.5.0.0
Ibm ≫ Websphere Service Registry And Repository Version 7.5.0.1
Ibm ≫ Websphere Service Registry And Repository Version 7.5.0.2
Ibm ≫ Websphere Service Registry And Repository Version 8.0
Ibm ≫ Websphere Service Registry And Repository Version 8.0.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.87% | 0.539 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
http://www.ibm.com/support/docview.wss?uid=swg21693379
http://www.ibm.com/support/docview.wss?uid=swg21693381
http://www.ibm.com/support/docview.wss?uid=swg21693384
http://www.ibm.com/support/docview.wss?uid=swg21693387
http://www-01.ibm.com/support/docview.wss?uid=swg1IV26727
http://www.securityfocus.com/bid/71906
https://exchange.xforce.ibmcloud.com/vulnerabilities/98553