Cross-Site Request Forgery Vulnerability in IBM WebSphere Application Server
CVE-2017-1194

8.8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
28 April 2017

Summary

IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 are susceptible to a cross-site request forgery vulnerability. This issue could enable an attacker to perform unauthorized actions on behalf of a trusted user, leveraging the trust established by the server. Malicious requests could be transmitted without the user's consent, allowing an attacker to exploit this vulnerability for various attacks. For further details on mitigation and coding approaches to enhance security, refer to the IBM documentation and security assessments.

Affected Version(s)

IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.