6.8
CVSSv2

CVE-2014-6106

Published: 18/09/2017 Updated: 22/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote malicious users to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm security identity manager 5.1.0

ibm security identity manager 5.1.0.3

ibm security identity manager 5.1.0.4

ibm security identity manager 5.1.0.5

ibm security identity manager 6.0.0.2

ibm security identity manager 6.0.0.3

ibm security identity manager 6.0.0.4

ibm security identity manager 5.1.0.7

ibm security identity manager 5.1.0.9

ibm security identity manager 5.1.0.14

ibm security identity manager 6.0.0.0

ibm security identity manager 5.1.0.10

ibm security identity manager 5.1.0.11

ibm security identity manager 5.1.0.12

ibm security identity manager 5.1.0.13

ibm security identity manager 7.0.0.0

ibm security identity manager 5.1.0.6

ibm security identity manager 5.1.0.8

ibm security identity manager 5.1.0.15

ibm security identity manager 6.0.0.1