CVE-2014-4816
Summary
| CVE | CVE-2014-4816 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-09-23 22:55:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Application Server | 6.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.0.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.11 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.13 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.15 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.17 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.7 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.1.9 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.11 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.13 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.15 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.17 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.19 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.22 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.23 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.24 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.25 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.27 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.28 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.29 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.30 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.31 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.32 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.33 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.35 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.37 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.39 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.41 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.43 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.6 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.7 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.0.2.9 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.11 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.12 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.13 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.14 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.15 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.17 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.19 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.21 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.23 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.25 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.27 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.29 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.31 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.33 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.35 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.37 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.39 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.41 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.43 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.45 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.47 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.7 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.9 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.10 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.11 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.12 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.13 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.14 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.15 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.16 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.17 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.18 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.19 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.21 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.22 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.23 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.24 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.25 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.27 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.29 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.31 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.33 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.6 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.7 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.8 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.9 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.6 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.7 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.8 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.9 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.0.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.5.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.5.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.5.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM Security Bulletin: Potential Security exposures with WebSphere Application Server (CVE-2014-4770 and CVE-2014-4816) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Vulnerability Note VU#573356 - IBM WebSphere Application Server contains multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| IBM WebSphere Application Server CVE-2014-4816 Cross Site Request Forgery Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA61423 - IBM WebSphere Application Server Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.