{"api_version":"1","generated_at":"2026-07-23T10:16:02+00:00","cve":"CVE-2007-5799","urls":{"html":"https://cve.report/CVE-2007-5799","api":"https://cve.report/api/cve/CVE-2007-5799.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5799","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5799"},"summary":{"title":"CVE-2007-5799","description":"Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-11-03 00:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-352","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://osvdb.org/41619","name":"http://osvdb.org/41619","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38179","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27448","name":"http://secunia.com/advisories/27448","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM WebSphere \"uddigui/navigateTree.do\" Cross-Site Scripting and Request Forgery - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26276","name":"http://www.securityfocus.com/bid/26276","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Application Server UDDI Console Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1018884","name":"http://www.securitytracker.com/id?1018884","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Application Server Input Validation Hole in 'uddigui/navigateTree.do' Page Permits Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK50245","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK50245","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM PK50245: VALIDATION NEEDED FOR PARAMETERS THAT ARE PASSED TO THE         NAVIGATETREE.DO PAGE IN THE UDDI USER CONSOLE - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5799","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5799","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5799","vulnerable":"1","versionEndIncluding":"6.1.0.12","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:46:59.522Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"26276","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26276"},{"name":"27448","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27448"},{"name":"PK50245","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK50245"},{"name":"websphere-navigatetree-csrf(38179)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38179"},{"name":"41619","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/41619"},{"name":"1018884","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018884"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"26276","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26276"},{"name":"27448","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27448"},{"name":"PK50245","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK50245"},{"name":"websphere-navigatetree-csrf(38179)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38179"},{"name":"41619","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/41619"},{"name":"1018884","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018884"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5799","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"26276","refsource":"BID","url":"http://www.securityfocus.com/bid/26276"},{"name":"27448","refsource":"SECUNIA","url":"http://secunia.com/advisories/27448"},{"name":"PK50245","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PK50245"},{"name":"websphere-navigatetree-csrf(38179)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38179"},{"name":"41619","refsource":"OSVDB","url":"http://osvdb.org/41619"},{"name":"1018884","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018884"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5799","datePublished":"2007-11-03T00:00:00.000Z","dateReserved":"2007-11-02T00:00:00.000Z","dateUpdated":"2024-08-07T15:46:59.522Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-11-03 00:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-352","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*","versionEndIncluding":"6.1.0.12","matchCriteriaId":"35D4889F-095E-43DE-9B41-DEFBFA36025E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5799","Ordinal":"1","Title":"CVE-2007-5799","CVE":"CVE-2007-5799","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5799","Ordinal":"1","NoteData":"Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.","Type":"Description","Title":"CVE-2007-5799"},{"CveYear":"2007","CveId":"5799","Ordinal":"2","NoteData":"2007-11-02","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5799","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}