Cross-site request forgery in IBM WebSphere Application Server - CVE-2017-1194
Published: May 1, 2017
IBM WebSphere Application Server
Detailed vulnerability description
The vulnerability allows a remote attacker to perform CSRF attack.
The vulnerability exists due to improper validation of the HTTP request origin within the OAuth service provider. A remote attacker can create a specially crafted web page, trick the victim into opening it and perform certain actions on the WebSphere Application Server with privileges of the current user.
How to mitigate CVE-2017-1194
Apply the iterim fix PI77770.