Loading
Generated remediation guidance and an executive summary. No account required.
Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.
Use CWE-352, Openwebanalytics vendor hub and Open Web Analytics product page to widen CVE-2014-1457 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-24637, CVE-2014-2294 and CVE-2014-1206 for nearby disclosures in the same product family.