IBM InfoSphere Information Server CVE-2013-4057 Cross Site Request Forgery Vulnerability
BID:66154
Info
IBM InfoSphere Information Server CVE-2013-4057 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 66154 |
| Class: | Design Error |
| CVE: |
CVE-2013-4057 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2014 12:00AM |
| Updated: | Jul 14 2014 03:47PM |
| Credit: | IBM |
| Vulnerable: |
IBM InfoSphere Information Server 8.5 IBM InfoSphere Information Server 8.1 IBM InfoSphere Information Server 8.0 |
| Not Vulnerable: | |
Discussion
IBM InfoSphere Information Server CVE-2013-4057 Cross Site Request Forgery Vulnerability
IBM InfoSphere Information Server is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 are vulnerable; other versions may also be affected.
IBM InfoSphere Information Server is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 are vulnerable; other versions may also be affected.
Exploit / POC
IBM InfoSphere Information Server CVE-2013-4057 Cross Site Request Forgery Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
IBM InfoSphere Information Server CVE-2013-4057 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM InfoSphere Information Server CVE-2013-4057 Cross Site Request Forgery Vulnerability
References:
References:
- IBM Homepage (IBM)
- IBM InfoSphere Information Server (IBM)