CVE-2013-5427
Summary
| CVE | CVE-2013-5427 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-04 05:39:08 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP8 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote attackers to hijack the authentication of arbitrary users. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS: 0.001030000 probability, percentile 0.277120000 (date 2026-05-04)
Problem Types: CWE-352 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Infosphere Master Data Management Collaboration Server | 10.0 | All | All | All |
| Application | Ibm | Infosphere Master Data Management Collaboration Server | 10.1 | All | All | All |
| Application | Ibm | Infosphere Master Data Management Collaboration Server | 11.0 | All | All | All |
| Application | Ibm | Infosphere Master Data Management Server For Product Information Management | 9.0 | All | All | All |
| Application | Ibm | Infosphere Master Data Management Server For Product Information Management | 9.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Cross-Site Request Forgery in IBM InfoSphere Master Data Management - Collaborative Edition (CVE-2013-5427) | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.