CVE-2014-0969

Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary users.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
ibminfosphere_master_data_management
10.0
ibminfosphere_master_data_management
10.1
ibminfosphere_master_data_management
11.0
ibminfosphere_master_data_management
11.3
ibminfosphere_master_data_management_server_for_product_information_management
9.0
ibminfosphere_master_data_management_server_for_product_information_management
9.1
ibminfosphere_master_data_management_server_for_product_information_management
10.0
ibminfosphere_master_data_management_server_for_product_information_management
10.0.0.1
ibminfosphere_master_data_management_server_for_product_information_management
10.0.1
ibminfosphere_master_data_management_server_for_product_information_management
10.1
ibminfosphere_master_data_management_server_for_product_information_management
10.1.0.1
ibminfosphere_master_data_management_server_for_product_information_management
10.1.0.2
ibminfosphere_master_data_management_server_for_product_information_management
11.0
ibminfosphere_master_data_management_server_for_product_information_management
11.3
𝑥
= Vulnerable software versions