CVE-2014-3061: IBM Emptoris Spend Analysis
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected products
- IBM Emptoris Spend Analysis: version 9.5.0.0 only; version 9.5.0.1 only; version 9.5.0.2 only; version 9.5.0.3 only; version 10.0.1.0 only; version 10.0.1.1 only; …
Published 2014-08-26. Last modified 2026-06-17.