First published: Thu May 03 2012(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allow remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational AppScan | =5.2 | |
IBM Rational AppScan | =5.4 | |
IBM Rational AppScan | =5.5.0 | |
IBM Rational AppScan | =5.5.0.1 | |
IBM Rational AppScan | =5.5.0.2 | |
IBM Rational AppScan | =5.6.0 | |
IBM Rational AppScan | =5.6.0.3 | |
IBM Rational AppScan | =8.0.0 | |
IBM Rational AppScan | =8.0.0.1 | |
IBM Rational AppScan | =8.0.0.2 | |
IBM Rational AppScan | =8.0.0.3 | |
IBM Rational AppScan | =8.0.1 | |
IBM Rational AppScan | =8.0.1.1 | |
IBM Rational AppScan | =8.5.0 | |
IBM Rational AppScan | =8.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0730 has a moderate severity rating, as it affects the authentication of administrators.
To fix CVE-2012-0730, you should upgrade IBM Rational AppScan Enterprise to version 8.5.0.1 or later.
CVE-2012-0730 enables cross-site request forgery (CSRF) attacks, allowing remote attackers to hijack administrative accounts.
CVE-2012-0730 affects IBM Rational AppScan Enterprise versions 5.x and 8.x before version 8.5.0.1.
Administrators of IBM Rational AppScan Enterprise systems can be affected by the exploitation of CVE-2012-0730.