CSRF Vulnerability in IBM WebSphere Portal 8.5.0 before CF03 Allows Authentication Hijacking and XSS Injection

CSRF Vulnerability in IBM WebSphere Portal 8.5.0 before CF03 Allows Authentication Hijacking and XSS Injection

CVE-2014-6125 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Learn more about our Cis Benchmark Audit For Ibm I.