First published: Fri Apr 28 2017(Updated: )
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =7.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1194 has a medium severity rating due to its potential for cross-site request forgery attacks.
To fix CVE-2017-1194, apply the latest security patches provided by IBM for WebSphere Application Server.
CVE-2017-1194 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0.
CVE-2017-1194 allows attackers to perform cross-site request forgery, which can lead to unauthorized actions on behalf of trusted users.
Yes, user interaction is required to exploit CVE-2017-1194, as it relies on the victim's browser to send malicious requests.