First published: Sun Mar 16 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Analyzer | =8.5 | |
IBM InfoSphere Information Analyzer | =8.5.0.1 | |
IBM InfoSphere Information Analyzer | =8.5.0.2 | |
IBM InfoSphere Information Analyzer | =8.5.0.3 | |
IBM InfoSphere Information Analyzer | =8.7 | |
IBM InfoSphere Information Analyzer | =8.7.0.1 | |
IBM InfoSphere Information Analyzer | =8.7.0.2 | |
IBM InfoSphere Information Analyzer | =9.1 | |
IBM InfoSphere Information Analyzer | =9.1.0.1 | |
IBM InfoSphere Information Analyzer | =9.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4057 is considered a high severity vulnerability due to its ability to allow attackers to hijack user authentication.
To resolve CVE-2013-4057, you should apply the latest patches provided by IBM for the affected versions of InfoSphere Information Server.
CVE-2013-4057 affects IBM InfoSphere Information Server versions 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0.
CVE-2013-4057 is a cross-site request forgery (CSRF) vulnerability.
Yes, CVE-2013-4057 can potentially allow attackers to gain unauthorized access to users' authenticated sessions.