IBM WebSphere Application Server Unspecified Cross Site Request Forgery Vulnerability
BID:43875
Info
IBM WebSphere Application Server Unspecified Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 43875 |
| Class: | Design Error |
| CVE: |
CVE-2010-0785 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2010 12:00AM |
| Updated: | Mar 19 2015 08:31AM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Application Server 7.0 3 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 7.0 .12 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 7.0.0.7 IBM Websphere Application Server 7.0.0.5 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0 IBM Tivoli Common Reporting 1.2 |
| Not Vulnerable: |
IBM Websphere Application Server 7.0 .13 IBM Tivoli Common Reporting 1.2 Interim Fix 9 |
Discussion
IBM WebSphere Application Server Unspecified Cross Site Request Forgery Vulnerability
IBM WebSphere Application Server is prone to an unspecified cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user's session and gain unauthorized access to the affected application; other attacks are also possible.
IBM WebSphere Application Server 7.0 prior to 7.0.0.13 are vulnerable.
UPDATE (Oct 7, 2011): Further information suggests Websphere Application Server running on other operating systems besides z/OS is also affected.
IBM WebSphere Application Server is prone to an unspecified cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user's session and gain unauthorized access to the affected application; other attacks are also possible.
IBM WebSphere Application Server 7.0 prior to 7.0.0.13 are vulnerable.
UPDATE (Oct 7, 2011): Further information suggests Websphere Application Server running on other operating systems besides z/OS is also affected.
Exploit / POC
IBM WebSphere Application Server Unspecified Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
Solution / Fix
IBM WebSphere Application Server Unspecified Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM WebSphere Application Server Unspecified Cross Site Request Forgery Vulnerability
References:
References: