Cross-site request forgery in Swagger UI - CVE-2019-17495

 

Cross-site request forgery in Swagger UI - CVE-2019-17495

Published: October 11, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30727
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17495
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Affected software

Swagger UI
IBM Concert Software
IBM Cloud Transformation Advisor
IBM Sterling B2B Integrator
IBM Rational Build Forge
Oracle Banking APIs
IBM Cloud Application Business Insights
IBM Sterling Partner Engagement Manager
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Oracle Banking Platform
Oracle Utilities Framework
Oracle Banking Digital Experience
IBM Planning Analytics Workspace
Oracle Commerce Guided Search
Primavera Gateway

How to mitigate CVE-2019-17495

Update to version 3.23.11.

Swagger UI - update to 3.23.11
IBM Concert Software - update to 1.0.3
IBM Sterling B2B Integrator - update to 6.2.0.1
IBM Rational Build Forge - update to 8.0.0.29
IBM Cloud Application Business Insights - addressed in versions 1.1.3.1, 1.1.4.2
IBM Planning Analytics Workspace - update to 2.0.83
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.8, 6.2.0.6, 6.2.1.3, 6.2.2.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-5

External References

Related Security Bulletins