Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PM41526.Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PM41529.Upgrade to version 8.0.0.1.Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PM36734.Upgrade to version 7.0.0.19.Upgrade to version 6.1.0.41. | Apr 27, 2018 | Jul 18, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub