Cross-site request forgery in IBM WebSphere Application Server - CVE-2017-1194

 

Cross-site request forgery in IBM WebSphere Application Server - CVE-2017-1194

Published: May 1, 2017


Vulnerability identifier: #VU6396
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1194
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform CSRF attack.

The vulnerability exists due to improper validation of the HTTP request origin within the OAuth service provider. A remote attacker can create a specially crafted web page, trick the victim into opening it and perform certain actions on the WebSphere Application Server with privileges of the current user.


Affected software

IBM WebSphere Application Server

How to mitigate CVE-2017-1194

Apply the iterim fix PI77770.



External References

Related Security Bulletins