First published: Wed Nov 30 2016(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the set of available applications.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections Portlets | =4.0.0.0 | |
IBM Connections Portlets | =4.5.0.0 | |
IBM Connections Portlets | =5.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3004 is considered a moderate severity vulnerability due to its potential impact on user authentication.
To fix CVE-2016-3004, you should apply the latest security patches provided by IBM for the affected versions of Connections.
CVE-2016-3004 affects IBM Connections versions 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4.
CVE-2016-3004 is a Cross-site Request Forgery (CSRF) vulnerability.
Attackers can hijack the authentication of arbitrary users to make unauthorized changes to the application set.