6.8
CVSSv2

CVE-2014-4774

Published: 25/05/2015 Updated: 26/05/2015
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 prior to 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 prior to 9.1.0.2 allows remote malicious users to hijack the authentication of arbitrary users via vectors involving a FRAME element.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm license metric tool 9.0.1

ibm endpoint manager family 9.0.1

ibm license metric tool 9.0

ibm license metric tool 9.1.0.1

ibm endpoint manager family 9.1.0