First published: Sun Oct 04 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere eXtreme Scale | =7.1.0 | |
IBM WebSphere eXtreme Scale | =7.1.0.2 | |
IBM WebSphere eXtreme Scale | =7.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2026 has a high severity rating due to its potential to allow unauthorized actions via CSRF attacks.
To fix CVE-2015-2026, upgrade IBM WebSphere eXtreme Scale to version 7.1.0.3 or 7.1.1.1 or later.
CVE-2015-2026 can facilitate attacks that hijack user sessions and execute arbitrary HTTP requests.
CVE-2015-2026 affects installations of IBM WebSphere eXtreme Scale versions 7.1.0 prior to 7.1.0.3 and 7.1.1 prior to 7.1.1.1.
An attacker exploiting CVE-2015-2026 can insert malicious XSS sequences into requests made on behalf of users.