CVE-2014-8900
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21695293
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | urbancode_deploy | {"endIncluding":"6.0.1.6"} | |
References
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.