IBM Lotus Protector for Mail Security Unspecified Cross-Site Request Forgery Vulnerability
BID:66404
Info
IBM Lotus Protector for Mail Security Unspecified Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 66404 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0885 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2014 12:00AM |
| Updated: | Mar 24 2014 12:00AM |
| Credit: | Alexander Klink |
| Vulnerable: |
IBM Lotus Protector for Mail Security 2.8 0 IBM Lotus Protector for Mail Security 2.8.1.0 |
| Not Vulnerable: | |
Discussion
IBM Lotus Protector for Mail Security Unspecified Cross-Site Request Forgery Vulnerability
IBM Lotus Protector for Mail Security is prone to an unspecified cross-site request-forgery vulnerability because it does not properly validate certain unspecified HTTP request.
An attacker can exploit this issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
IBM Lotus Protector for Mail Security 2.8.0.0 and 2.8.1.0 are vulnerable.
IBM Lotus Protector for Mail Security is prone to an unspecified cross-site request-forgery vulnerability because it does not properly validate certain unspecified HTTP request.
An attacker can exploit this issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
IBM Lotus Protector for Mail Security 2.8.0.0 and 2.8.1.0 are vulnerable.
References
IBM Lotus Protector for Mail Security Unspecified Cross-Site Request Forgery Vulnerability
References:
References: