CVE-2014-6187 β€” Cross-Site Request Forgery in IBM Websphere Service Registry AND Repository

Severity
6.0MEDIUMNVD
EPSS
0.3%
top 51.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24
Latest updateMay 17

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x before 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages1 packages

πŸ”΄Vulnerability Details

2
GHSA
GHSA-8g7r-fpwr-v4xx: Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6β†—2022-05-17
β–Ά
CVEList
CVE-2014-6187: Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6β†—2014-12-24
β–Ά
CVE-2014-6187 β€” Cross-Site Request Forgery in IBM | cvebase