Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21686241 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95635 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ibm
Published: 2014-10-29T10:00:00
Updated: 2017-08-28T12:57:01
Reserved: 2014-07-09T00:00:00
Link: CVE-2014-4839
JSON object: View
NVD Information
Status : Modified
Published: 2014-10-29T10:55:04.540
Modified: 2017-08-29T01:35:09.890
Link: CVE-2014-4839
JSON object: View
Redhat Information
No data.
CWE