CVE-2017-1194: CSRF
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1194?
CVE-2017-1194 has a medium severity rating due to its potential for cross-site request forgery attacks.
How do I fix CVE-2017-1194?
To fix CVE-2017-1194, apply the latest security patches provided by IBM for WebSphere Application Server.
What versions of IBM WebSphere Application Server are affected by CVE-2017-1194?
CVE-2017-1194 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0.
What type of attack does CVE-2017-1194 allow?
CVE-2017-1194 allows attackers to perform cross-site request forgery, which can lead to unauthorized actions on behalf of trusted users.
Is user intervention required to exploit CVE-2017-1194?
Yes, user interaction is required to exploit CVE-2017-1194, as it relies on the victim's browser to send malicious requests.