First published: Wed Aug 21 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server | =8.0.0.0 | |
IBM WebSphere Application Server | =8.0.0.1 | |
IBM WebSphere Application Server | =8.0.0.2 | |
IBM WebSphere Application Server | =8.0.0.3 | |
IBM WebSphere Application Server | =8.0.0.4 | |
IBM WebSphere Application Server | =8.0.0.5 | |
IBM WebSphere Application Server | =8.0.0.6 | |
IBM WebSphere Application Server | =7.0 | |
IBM WebSphere Application Server | =7.0.0.1 | |
IBM WebSphere Application Server | =7.0.0.2 | |
IBM WebSphere Application Server | =7.0.0.3 | |
IBM WebSphere Application Server | =7.0.0.4 | |
IBM WebSphere Application Server | =7.0.0.5 | |
IBM WebSphere Application Server | =7.0.0.6 | |
IBM WebSphere Application Server | =7.0.0.7 | |
IBM WebSphere Application Server | =7.0.0.8 | |
IBM WebSphere Application Server | =7.0.0.9 | |
IBM WebSphere Application Server | =7.0.0.10 | |
IBM WebSphere Application Server | =7.0.0.11 | |
IBM WebSphere Application Server | =7.0.0.12 | |
IBM WebSphere Application Server | =7.0.0.13 | |
IBM WebSphere Application Server | =7.0.0.14 | |
IBM WebSphere Application Server | =7.0.0.15 | |
IBM WebSphere Application Server | =7.0.0.16 | |
IBM WebSphere Application Server | =7.0.0.17 | |
IBM WebSphere Application Server | =7.0.0.18 | |
IBM WebSphere Application Server | =7.0.0.19 | |
IBM WebSphere Application Server | =7.0.0.21 | |
IBM WebSphere Application Server | =7.0.0.22 | |
IBM WebSphere Application Server | =7.0.0.23 | |
IBM WebSphere Application Server | =7.0.0.24 | |
IBM WebSphere Application Server | =7.0.0.25 | |
IBM WebSphere Application Server | =7.0.0.27 | |
IBM WebSphere Application Server | =7.0.0.29 | |
IBM WebSphere Application Server | =8.5.0.0 | |
IBM WebSphere Application Server | =8.5.0.1 | |
IBM WebSphere Application Server | =8.5.0.2 | |
IBM WebSphere Application Server | =6.1 | |
IBM WebSphere Application Server | =6.1.0 | |
IBM WebSphere Application Server | =6.1.0.0 | |
IBM WebSphere Application Server | =6.1.0.1 | |
IBM WebSphere Application Server | =6.1.0.2 | |
IBM WebSphere Application Server | =6.1.0.3 | |
IBM WebSphere Application Server | =6.1.0.5 | |
IBM WebSphere Application Server | =6.1.0.7 | |
IBM WebSphere Application Server | =6.1.0.9 | |
IBM WebSphere Application Server | =6.1.0.11 | |
IBM WebSphere Application Server | =6.1.0.12 | |
IBM WebSphere Application Server | =6.1.0.13 | |
IBM WebSphere Application Server | =6.1.0.14 | |
IBM WebSphere Application Server | =6.1.0.15 | |
IBM WebSphere Application Server | =6.1.0.17 | |
IBM WebSphere Application Server | =6.1.0.19 | |
IBM WebSphere Application Server | =6.1.0.21 | |
IBM WebSphere Application Server | =6.1.0.23 | |
IBM WebSphere Application Server | =6.1.0.25 | |
IBM WebSphere Application Server | =6.1.0.27 | |
IBM WebSphere Application Server | =6.1.0.29 | |
IBM WebSphere Application Server | =6.1.0.31 | |
IBM WebSphere Application Server | =6.1.0.33 | |
IBM WebSphere Application Server | =6.1.0.35 | |
IBM WebSphere Application Server | =6.1.0.37 | |
IBM WebSphere Application Server | =6.1.0.39 | |
IBM WebSphere Application Server | =6.1.0.41 | |
IBM WebSphere Application Server | =6.1.0.43 | |
IBM WebSphere Application Server | =6.1.0.45 | |
IBM WebSphere Application Server | =6.1.1 | |
IBM WebSphere Application Server | =6.1.3 | |
IBM WebSphere Application Server | =6.1.5 | |
IBM WebSphere Application Server | =6.1.6 | |
IBM WebSphere Application Server | =6.1.7 | |
IBM WebSphere Application Server | =6.1.13 | |
IBM WebSphere Application Server | =6.1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3029 has a medium severity rating due to its potential for cross-site request forgery attacks.
To fix CVE-2013-3029, upgrade your IBM WebSphere Application Server to version 6.1.0.47, 7.0.0.31, 8.0.0.7, or 8.5.5.1 or later.
CVE-2013-3029 affects IBM WebSphere Application Server versions 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1.
CVE-2013-3029 is classified as a cross-site request forgery (CSRF) vulnerability.
Remote attackers can exploit CVE-2013-3029 to hijack the authentication of arbitrary users on affected systems.