Vulnerability Bulletins |
IBM Security Bulletin: IBM UrbanCode Release is vulnerable to a cross-site request forgery allowing a malicious site to force log-out (CVE-2014-8900) |
|
| Affected software | IBM |
|
IBM UrbanCode Release is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities. CVE(s): CVE-2014-8900 Affected product(s) and affected version(s): IBM UrbanCode Release 6.0.1.6 and earlier, More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_urbancode_release_is_vulnerable_to_a_cross_site_request_forgery_allowing_a_malicious_site_to_force_log_out_cve_2014_8900?lang=en_us |
|






