CVE-2014-6125
published 2014-10-28CVE-2014-6125: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary…
PriorityP424medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.97%
58.2th percentile
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_portal | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-87f7-rq2h-978j: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8
ghsa_unreviewed·2022-05-17
CVE-2014-6125 [MEDIUM] CWE-352 GHSA-87f7-rq2h-978j: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Red Hat
nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)
vendor_redhat·2014-03-18·CVSS 4.3
CVE-2014-1492 [MEDIUM] CWE-172 nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)
nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
It was found that the implementation of Internationalizing Domain Names in Applications (IDNA) hostname matching in NSS did not follow the RFC 6125 recommendations. This could lead to certain invalid certificates with international characters to be accepted as valid.
No detection rules found.
No public exploits indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1PI26889http://www-01.ibm.com/support/docview.wss?uid=swg21684651http://www.securityfocus.com/bid/70759https://exchange.xforce.ibmcloud.com/vulnerabilities/96782http://www-01.ibm.com/support/docview.wss?uid=swg1PI26889http://www-01.ibm.com/support/docview.wss?uid=swg21684651http://www.securityfocus.com/bid/70759https://exchange.xforce.ibmcloud.com/vulnerabilities/96782
2014-10-28
Published