First published: Wed Nov 14 2012(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger information disclosure.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server | =6.1 | |
IBM WebSphere Application Server | =6.1.0 | |
IBM WebSphere Application Server | =6.1.0.0 | |
IBM WebSphere Application Server | =6.1.0.1 | |
IBM WebSphere Application Server | =6.1.0.2 | |
IBM WebSphere Application Server | =6.1.0.3 | |
IBM WebSphere Application Server | =6.1.0.5 | |
IBM WebSphere Application Server | =6.1.0.7 | |
IBM WebSphere Application Server | =6.1.0.9 | |
IBM WebSphere Application Server | =6.1.0.11 | |
IBM WebSphere Application Server | =6.1.0.12 | |
IBM WebSphere Application Server | =6.1.0.15 | |
IBM WebSphere Application Server | =6.1.0.17 | |
IBM WebSphere Application Server | =6.1.0.19 | |
IBM WebSphere Application Server | =6.1.0.21 | |
IBM WebSphere Application Server | =6.1.0.23 | |
IBM WebSphere Application Server | =6.1.0.25 | |
IBM WebSphere Application Server | =6.1.0.27 | |
IBM WebSphere Application Server | =6.1.0.29 | |
IBM WebSphere Application Server | =6.1.0.31 | |
IBM WebSphere Application Server | =6.1.0.33 | |
IBM WebSphere Application Server | =6.1.0.35 | |
IBM WebSphere Application Server | =6.1.0.37 | |
IBM WebSphere Application Server | =6.1.0.39 | |
IBM WebSphere Application Server | =6.1.0.41 | |
IBM WebSphere Application Server | =6.1.0.43 | |
IBM WebSphere Application Server | =6.1.1 | |
IBM WebSphere Application Server | =6.1.3 | |
IBM WebSphere Application Server | =6.1.5 | |
IBM WebSphere Application Server | =6.1.6 | |
IBM WebSphere Application Server | =6.1.7 | |
IBM WebSphere Application Server | =6.1.13 | |
IBM WebSphere Application Server | =6.1.14 | |
IBM WebSphere Application Server | =7.0 | |
IBM WebSphere Application Server | =7.0.0.1 | |
IBM WebSphere Application Server | =7.0.0.2 | |
IBM WebSphere Application Server | =7.0.0.3 | |
IBM WebSphere Application Server | =7.0.0.4 | |
IBM WebSphere Application Server | =7.0.0.5 | |
IBM WebSphere Application Server | =7.0.0.6 | |
IBM WebSphere Application Server | =7.0.0.7 | |
IBM WebSphere Application Server | =7.0.0.8 | |
IBM WebSphere Application Server | =7.0.0.9 | |
IBM WebSphere Application Server | =7.0.0.11 | |
IBM WebSphere Application Server | =7.0.0.13 | |
IBM WebSphere Application Server | =7.0.0.15 | |
IBM WebSphere Application Server | =7.0.0.17 | |
IBM WebSphere Application Server | =7.0.0.19 | |
IBM WebSphere Application Server | =7.0.0.21 | |
IBM WebSphere Application Server | =7.0.0.23 | |
IBM WebSphere Application Server | =8.0.0.0 | |
IBM WebSphere Application Server | =8.0.0.1 | |
IBM WebSphere Application Server | =8.0.0.2 | |
IBM WebSphere Application Server | =8.0.0.3 | |
IBM WebSphere Application Server | =8.0.0.4 | |
IBM WebSphere Application Server | =8.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-4853 is classified as medium, as it allows unauthorized access to sensitive information due to CSRF vulnerabilities.
To fix CVE-2012-4853, upgrade the IBM WebSphere Application Server to the latest version available that is not affected by this vulnerability.
CVE-2012-4853 affects IBM WebSphere Application Server versions 6.1, 7.0, 8.0, and 8.5 before their respective patch releases.
Yes, CVE-2012-4853 can lead to data breaches by allowing attackers to hijack user sessions and access sensitive information.
CVE-2012-4853 is a cross-site request forgery (CSRF) vulnerability.