Thursday, August 28, 2014

IBM Security Bulletin: Cross-site Request Forgery Vulnerability Addressed in Asset and Service Management (CVE-2014-3024)

IBM Maximo Asset Management is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request. An attacker...



from IBM Product Security Incident Response Team http://ibm.co/1zMy01P

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.