CVE-2012-3294: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File Transfer 7.5, allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add user accounts via the /wmqfteconsole/Filespaces URI, (2) modify permissions via the /wmqfteconsole/FileSpacePermisssions URI, or (3) add MQ Message Descriptor (MQMD) user accounts via the /wmqfteconsole/UploadUsers URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3294?
CVE-2012-3294 is considered to have a medium severity level due to its ability to allow CSRF attacks leading to unauthorized actions within the application.
How do I fix CVE-2012-3294?
To fix CVE-2012-3294, ensure that you upgrade to a version of IBM WebSphere MQ File Transfer Edition later than 7.0.4 or IBM WebSphere MQ Managed File Transfer later than 7.5.
Who is affected by CVE-2012-3294?
CVE-2012-3294 affects users of IBM WebSphere MQ File Transfer Edition versions 7.0.4 and earlier, as well as IBM WebSphere MQ Managed File Transfer version 7.5.
What type of vulnerability is CVE-2012-3294?
CVE-2012-3294 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
What could attackers do with CVE-2012-3294?
Attackers exploiting CVE-2012-3294 could hijack the authentication of users to execute unauthorized commands and actions.