IBM WebSphere Application Server CVE-2014-4816 Cross Site Request Forgery Vulnerability
BID:69980
Info
IBM WebSphere Application Server CVE-2014-4816 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 69980 |
| Class: | Design Error |
| CVE: |
CVE-2014-4816 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 18 2014 12:00AM |
| Updated: | Apr 13 2015 09:09PM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere Application Server for z/OS 7.0.0.20 IBM Websphere Application Server 8.5.5 IBM Websphere Application Server 8.0 2 IBM Websphere Application Server 8.0 1 IBM Websphere Application Server 7.0 3 IBM Websphere Application Server 7.0 29 IBM Websphere Application Server 7.0 21 IBM Websphere Application Server 7.0 10 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 7.0 .2 IBM Websphere Application Server 7.0 .13 IBM Websphere Application Server 7.0 .12 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.1 41 IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .33 IBM Websphere Application Server 6.1 .32 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .25 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 6.0.2 IBM Websphere Application Server 8.5.5.3 IBM Websphere Application Server 8.5.5.2 IBM Websphere Application Server 8.5.5.1 IBM Websphere Application Server 8.5.5.0 IBM Websphere Application Server 8.5.0.2 IBM Websphere Application Server 8.5.0.1 IBM Websphere Application Server 8.5.0.0 IBM Websphere Application Server 8.5 IBM Websphere Application Server 8.0.0.9 IBM Websphere Application Server 8.0.0.8 IBM Websphere Application Server 8.0.0.7 IBM Websphere Application Server 8.0.0.6 IBM Websphere Application Server 8.0.0.5 IBM Websphere Application Server 8.0.0.4 IBM Websphere Application Server 8.0.0.4 IBM Websphere Application Server 8.0.0.3 IBM Websphere Application Server 8.0.0.1 IBM Websphere Application Server 8.0.0.0 IBM Websphere Application Server 8.0 IBM Websphere Application Server 7.0.0.7 IBM Websphere Application Server 7.0.0.6 IBM Websphere Application Server 7.0.0.5 IBM Websphere Application Server 7.0.0.4 IBM Websphere Application Server 7.0.0.33 IBM Websphere Application Server 7.0.0.31 IBM Websphere Application Server 7.0.0.27 IBM Websphere Application Server 7.0.0.25 IBM Websphere Application Server 7.0.0.24 IBM Websphere Application Server 7.0.0.23 IBM Websphere Application Server 7.0.0.22 IBM Websphere Application Server 7.0.0.19 IBM Websphere Application Server 7.0.0.18 IBM Websphere Application Server 7.0.0.17 IBM Websphere Application Server 7.0.0.16 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.14 IBM Websphere Application Server 7.0.0.13 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0.0.0 IBM Websphere Application Server 7.0 IBM Websphere Application Server 7 IBM Websphere Application Server 6.1.0.47 IBM Websphere Application Server 6.1.0.45 IBM Websphere Application Server 6.1.0.43 IBM Websphere Application Server 6.1.0.39 IBM Websphere Application Server 6.1.0.37 IBM Websphere Application Server 6.1.0.35 IBM Websphere Application Server 6.1.0.34 IBM Websphere Application Server 6.1.0.33 IBM Websphere Application Server 6.1.0.31 IBM Websphere Application Server 6.1.0.29 IBM Websphere Application Server 6.1.0.27 IBM Websphere Application Server 6.1 |
| Not Vulnerable: |
IBM Websphere Application Server 8.5.5.4 IBM Websphere Application Server 8.0.0.10 IBM Websphere Application Server 7.0.0.35 |
Discussion
IBM WebSphere Application Server CVE-2014-4816 Cross Site Request Forgery Vulnerability
IBM WebSphere Application Server is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
IBM WebSphere Application Server is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Solution / Fix
IBM WebSphere Application Server CVE-2014-4816 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.