CVE-2007-5799: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
IBM WebSphere Application Server UDDI users are exposed when they use the UDDI user console on affected releases before 6.1.0 Fix Pack 13 (6.1.0.13). Exploitation is remote and does not require attacker authentication, but relies on actions being performed in the context of a UDDI user.
What does an attacker need to exploit it?
An attacker needs to cause a WAS UDDI user to submit a forged request to uddigui/navigateTree.do. The affected request parameters are keyField, nameField, valueField, and frameReturn.
What is the available remediation?
Upgrade to IBM WebSphere Application Server 6.1.0 Fix Pack 13 (6.1.0.13) or later. The provided data does not identify a workaround for environments that cannot patch immediately.