CVE-2014-0969
17.08.2014, 23:55
Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary users.
Vendor | Product | Version |
---|---|---|
ibm | infosphere_master_data_management | 10.0 |
ibm | infosphere_master_data_management | 10.1 |
ibm | infosphere_master_data_management | 11.0 |
ibm | infosphere_master_data_management | 11.3 |
ibm | infosphere_master_data_management_server_for_product_information_management | 9.0 |
ibm | infosphere_master_data_management_server_for_product_information_management | 9.1 |
ibm | infosphere_master_data_management_server_for_product_information_management | 10.0 |
ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.0.1 |
ibm | infosphere_master_data_management_server_for_product_information_management | 10.0.1 |
ibm | infosphere_master_data_management_server_for_product_information_management | 10.1 |
ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.1 |
ibm | infosphere_master_data_management_server_for_product_information_management | 10.1.0.2 |
ibm | infosphere_master_data_management_server_for_product_information_management | 11.0 |
ibm | infosphere_master_data_management_server_for_product_information_management | 11.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References