Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21695293 | vendor advisory |
http://www.securityfocus.com/bid/72900 | vdb entry third party advisory |