First published: Wed Feb 21 2018(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111813.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM TRIRIGA Application Platform | =3.3.0.0 | |
IBM TRIRIGA Application Platform | =3.3.1.0 | |
IBM TRIRIGA Application Platform | =3.3.2.0 | |
IBM TRIRIGA Application Platform | =3.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0348 has a medium severity rating due to its potential to allow unauthorized actions through CSRF.
To mitigate CVE-2016-0348, it is recommended to update to a patched version of the IBM TRIRIGA Application Platform to eliminate CSRF vulnerabilities.
CVE-2016-0348 affects users of IBM TRIRIGA Application Platform versions 3.3.0.0, 3.3.1.0, 3.3.2.0, and 3.4.0.0.
CVE-2016-0348 allows attackers to hijack user authentication for requests that can lead to the insertion of XSS sequences.
CVE-2016-0348 is a known vulnerability that has been identified within specific versions of IBM TRIRIGA, making it important for users to be aware.