PT-2014-3568 · Serena · Serena Dimensions Cm

Ken Cijsouw

·

Published

2014-03-06

·

Updated

2014-03-07

·

CVE-2014-0336

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Serena Dimensions CM version 12.2 build 7.199.0
Description A cross-site request forgery (CSRF) issue exists, allowing remote attackers to hijack the authentication of administrators for requests that use the user new master parameter to the "adminconsole/" API endpoint.
Recommendations For Serena Dimensions CM version 12.2 build 7.199.0, consider disabling access to the "adminconsole/" API endpoint until a fix is available, or restrict the use of the user new master parameter to prevent exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0336

Affected Products

Serena Dimensions Cm