First published: Thu Feb 16 2017(Updated: )
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 Identity Server | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.