← Vulnerability feed

Vulnerability record · CVE-2014-6077 · published 18 December 2014

CVE-2014-6077: Ibm security access manager for web cross-site request forgery vulnerability

Ibm · Security Access Manager For Web

Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

6.8 CVSS 2.0 Medium EPSS 0.63% · top 51.7% CWE-352 · Cross-site request forgery
6.8CVSS 2.0 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-6077 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2016-3028Ibm security access manager os command injection vulnerabilityIBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authent…EPSS 3.5%8.1CVE-2016-3025Ibm security access manager vulnerabilityIBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed logi…EPSS 1.6%7.8CVE-2013-6329Ibm content manager ondemand for multiplatforms vulnerabilityIBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of…EPSS 3.2%7.5CVE-2017-1473Ibm security access manager for web firmware inadequate encryption strength vulnerabilityIBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could a…EPSS 0.87%7.5CVE-2016-5919Ibm security access manager for web 7.0 firmware inadequate encryption strength vulnerabilityIBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decryp…EPSS 0.69%7.5CVE-2015-4963Ibm security access manager for web vulnerabilityIBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote at…EPSS 3.3%6.5CVE-2014-6080Ibm security access manager for mobile sql injection vulnerabilitySQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and …EPSS 1.0%6.1CVE-2017-1534Ibm security access manager for web firmware open redirect vulnerabilityIBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By pe…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2014-6077), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.