CVE-2015-0116

IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict the addition of links, which makes it easier for remote authenticated users to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
References
Link Resource
http://www-01.ibm.com/support/docview.wss?uid=swg21902807 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:leads:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:leads:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:leads:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:leads:8.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:leads:8.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:leads:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:leads:8.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:leads:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:leads:9.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:leads:9.1.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-06-28 22:59

Updated : 2024-02-04 18:53


NVD link : CVE-2015-0116

Mitre link : CVE-2015-0116

CVE.ORG link : CVE-2015-0116


JSON object : View

Products Affected

ibm

  • leads
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')