IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict the addition of links, which makes it easier for remote authenticated users to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21902807 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2015-06-28T22:00:00
Updated: 2024-08-06T03:55:28.023Z
Reserved: 2014-11-18T00:00:00
Link: CVE-2015-0116
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-06-28T22:59:02.567
Modified: 2024-11-21T02:22:23.807
Link: CVE-2015-0116
Redhat
No data.