CVE-2014-3058

MEDIUM
CVSS v3
6.0CVSS v2
0.10% EPSS (exploit probability)
CWE-352CWE

Description

Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch Status
Ubiquiti Ubiquiti EdgeRouter X Unpatched

External references