Multiple IBM InfoSphere Master Data Management Products CVE-2014-0970 Link Injection Vulnerability
BID:69025
Info
Multiple IBM InfoSphere Master Data Management Products CVE-2014-0970 Link Injection Vulnerability
| Bugtraq ID: | 69025 |
| Class: | Design Error |
| CVE: |
CVE-2014-0970 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2014 12:00AM |
| Updated: | Jul 02 2014 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Infosphere Master Data Management Server For Product Information 9.1 IBM Infosphere Master Data Management Server For Product Information 9.0 IBM InfoSphere Master Data Management - Collaborative Edition 11.0 IBM InfoSphere Master Data Management - Collaborative Edition 10.1 IBM InfoSphere Master Data Management - Collaborative Edition 10.0 |
| Not Vulnerable: | |
Discussion
Multiple IBM InfoSphere Master Data Management Products CVE-2014-0970 Link Injection Vulnerability
Multiple IBM InfoSphere Master Data Management Products are prone to a link injection vulnerability.
Attackers can exploit this issue to inject arbitrary links to different pages within the application. This may allow an attacker to perform phishing attacks by presenting false information that may appear to be legitimate application pages.
Multiple IBM InfoSphere Master Data Management Products are prone to a link injection vulnerability.
Attackers can exploit this issue to inject arbitrary links to different pages within the application. This may allow an attacker to perform phishing attacks by presenting false information that may appear to be legitimate application pages.
Exploit / POC
Multiple IBM InfoSphere Master Data Management Products CVE-2014-0970 Link Injection Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Multiple IBM InfoSphere Master Data Management Products CVE-2014-0970 Link Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.