IBM Sametime Proxy Server and Web Client CVE-2014-3015 Cross Site Request Forgery Vulnerability
BID:67598
Info
IBM Sametime Proxy Server and Web Client CVE-2014-3015 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 67598 |
| Class: | Design Error |
| CVE: |
CVE-2014-3015 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2014 12:00AM |
| Updated: | May 21 2014 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Sametime Proxy Server and Web Client 9.0.0.1 IBM Sametime Proxy Server and Web Client 9.0 |
| Not Vulnerable: | |
Discussion
IBM Sametime Proxy Server and Web Client CVE-2014-3015 Cross Site Request Forgery Vulnerability
IBM Sametime Proxy Server and Web Client is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
IBM Sametime Proxy Server and Web Client 9.0 and 9.0.0.1 are vulnerable.
IBM Sametime Proxy Server and Web Client is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
IBM Sametime Proxy Server and Web Client 9.0 and 9.0.0.1 are vulnerable.
Solution / Fix
IBM Sametime Proxy Server and Web Client CVE-2014-3015 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Sametime Proxy Server and Web Client CVE-2014-3015 Cross Site Request Forgery Vulnerability
References:
References: