IBM WebSphere Application Server CVE-2013-0460 Cross-Site Request Forgery Vulnerability
BID:57510
Info
IBM WebSphere Application Server CVE-2013-0460 Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 57510 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0460 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2013 12:00AM |
| Updated: | Jan 16 2014 05:15PM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Application Server 8.0 2 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 7.0 .2 IBM Websphere Application Server 7.0 .12 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.1 41 IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .33 IBM Websphere Application Server 6.1 .32 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .25 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 8.0.0.4 IBM Websphere Application Server 8.0.0.1 IBM Websphere Application Server 8.0.0.0 IBM Websphere Application Server 8.0 IBM Websphere Application Server 7.0.0.7 IBM Websphere Application Server 7.0.0.6 IBM Websphere Application Server 7.0.0.5 IBM Websphere Application Server 7.0.0.4 IBM Websphere Application Server 7.0.0.23 IBM Websphere Application Server 7.0.0.19 IBM Websphere Application Server 7.0.0.17 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.14 IBM Websphere Application Server 7.0.0.13 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0.0.0 IBM Websphere Application Server 7.0 IBM Websphere Application Server 6.1.0.45 IBM Websphere Application Server 6.1.0.43 IBM Websphere Application Server 6.1.0.39 IBM Websphere Application Server 6.1.0.37 IBM Websphere Application Server 6.1.0.35 IBM Websphere Application Server 6.1.0.34 IBM Websphere Application Server 6.1.0.31 IBM Websphere Application Server 6.1.0.29 IBM Websphere Application Server 6.1.0.27 IBM Websphere Application Server 6.1 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server CVE-2013-0460 Cross-Site Request Forgery Vulnerability
IBM WebSphere Application Server is prone to a cross-site request forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user and gain access to the affected application; other attacks are also possible.
IBM WebSphere Application Server versions 6.1 and 7 are affected.
IBM WebSphere Application Server is prone to a cross-site request forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user and gain access to the affected application; other attacks are also possible.
IBM WebSphere Application Server versions 6.1 and 7 are affected.
Exploit / POC
IBM WebSphere Application Server CVE-2013-0460 Cross-Site Request Forgery Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to visit a malicious Web page.
To exploit this issue an attacker must entice an unsuspecting victim to visit a malicious Web page.
Solution / Fix
IBM WebSphere Application Server CVE-2013-0460 Cross-Site Request Forgery Vulnerability
Solution:
Vendor fixes are available. Please see the references for more information.
Solution:
Vendor fixes are available. Please see the references for more information.
References
IBM WebSphere Application Server CVE-2013-0460 Cross-Site Request Forgery Vulnerability
References:
References:
- IBM Websphere Homepage (IBM)