First published: Wed Aug 21 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | =8.0.0.0 | |
Ibm Websphere Application Server | =8.0.0.1 | |
Ibm Websphere Application Server | =8.0.0.2 | |
Ibm Websphere Application Server | =8.0.0.3 | |
Ibm Websphere Application Server | =8.0.0.4 | |
Ibm Websphere Application Server | =8.0.0.5 | |
Ibm Websphere Application Server | =8.0.0.6 | |
Ibm Websphere Application Server | =7.0 | |
Ibm Websphere Application Server | =7.0.0.1 | |
Ibm Websphere Application Server | =7.0.0.2 | |
Ibm Websphere Application Server | =7.0.0.3 | |
Ibm Websphere Application Server | =7.0.0.4 | |
Ibm Websphere Application Server | =7.0.0.5 | |
Ibm Websphere Application Server | =7.0.0.6 | |
Ibm Websphere Application Server | =7.0.0.7 | |
Ibm Websphere Application Server | =7.0.0.8 | |
Ibm Websphere Application Server | =7.0.0.9 | |
Ibm Websphere Application Server | =7.0.0.10 | |
Ibm Websphere Application Server | =7.0.0.11 | |
Ibm Websphere Application Server | =7.0.0.12 | |
Ibm Websphere Application Server | =7.0.0.13 | |
Ibm Websphere Application Server | =7.0.0.14 | |
Ibm Websphere Application Server | =7.0.0.15 | |
Ibm Websphere Application Server | =7.0.0.16 | |
Ibm Websphere Application Server | =7.0.0.17 | |
Ibm Websphere Application Server | =7.0.0.18 | |
Ibm Websphere Application Server | =7.0.0.19 | |
Ibm Websphere Application Server | =7.0.0.21 | |
Ibm Websphere Application Server | =7.0.0.22 | |
Ibm Websphere Application Server | =7.0.0.23 | |
Ibm Websphere Application Server | =7.0.0.24 | |
Ibm Websphere Application Server | =7.0.0.25 | |
Ibm Websphere Application Server | =7.0.0.27 | |
Ibm Websphere Application Server | =7.0.0.29 | |
Ibm Websphere Application Server | =8.5.0.0 | |
Ibm Websphere Application Server | =8.5.0.1 | |
Ibm Websphere Application Server | =8.5.0.2 | |
Ibm Websphere Application Server | =6.1 | |
Ibm Websphere Application Server | =6.1.0 | |
Ibm Websphere Application Server | =6.1.0.0 | |
Ibm Websphere Application Server | =6.1.0.1 | |
Ibm Websphere Application Server | =6.1.0.2 | |
Ibm Websphere Application Server | =6.1.0.3 | |
Ibm Websphere Application Server | =6.1.0.5 | |
Ibm Websphere Application Server | =6.1.0.7 | |
Ibm Websphere Application Server | =6.1.0.9 | |
Ibm Websphere Application Server | =6.1.0.11 | |
Ibm Websphere Application Server | =6.1.0.12 | |
Ibm Websphere Application Server | =6.1.0.13 | |
Ibm Websphere Application Server | =6.1.0.14 | |
Ibm Websphere Application Server | =6.1.0.15 | |
Ibm Websphere Application Server | =6.1.0.17 | |
Ibm Websphere Application Server | =6.1.0.19 | |
Ibm Websphere Application Server | =6.1.0.21 | |
Ibm Websphere Application Server | =6.1.0.23 | |
Ibm Websphere Application Server | =6.1.0.25 | |
Ibm Websphere Application Server | =6.1.0.27 | |
Ibm Websphere Application Server | =6.1.0.29 | |
Ibm Websphere Application Server | =6.1.0.31 | |
Ibm Websphere Application Server | =6.1.0.33 | |
Ibm Websphere Application Server | =6.1.0.35 | |
Ibm Websphere Application Server | =6.1.0.37 | |
Ibm Websphere Application Server | =6.1.0.39 | |
Ibm Websphere Application Server | =6.1.0.41 | |
Ibm Websphere Application Server | =6.1.0.43 | |
Ibm Websphere Application Server | =6.1.0.45 | |
Ibm Websphere Application Server | =6.1.1 | |
Ibm Websphere Application Server | =6.1.3 | |
Ibm Websphere Application Server | =6.1.5 | |
Ibm Websphere Application Server | =6.1.6 | |
Ibm Websphere Application Server | =6.1.7 | |
Ibm Websphere Application Server | =6.1.13 | |
Ibm Websphere Application Server | =6.1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.