CVE-2015-5037
MEDIUMIBM Connections < 3.0.1.1 - CSRF
Title source: ruleDescription
Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Scores
CVSS v3
5.4
EPSS
0.0004
EPSS Percentile
13.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Classification
CWE
CWE-352
Status
draft
Affected Products (4)
ibm/connections
< 3.0.1.1
ibm/connections
ibm/connections
ibm/connections
Timeline
Published
Jan 03, 2016
Tracked Since
Feb 18, 2026