CVE-2014-0969
17.08.2014, 23:55
Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary users.
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_master_data_management | 10.0 |
| ibm | infosphere_master_data_management | 10.1 |
| ibm | infosphere_master_data_management | 11.0 |
| ibm | infosphere_master_data_management | 11.3 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.1 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.2 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 11.0 |
| ibm | infosphere_master_data_management_server_for_product_information_management | 11.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References