CVE-2019-13516: CSRF
Published Aug 15, 2019
·Updated
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.
Affected Software
1 affected component
OSIsoft PI Web API<=2018
Event History
Aug 15, 2019
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-13516?
CVE-2019-13516 is categorized with a medium severity due to lack of effective cross-site request forgery protection.
2
How do I fix CVE-2019-13516?
To address CVE-2019-13516, upgrade to a version of OSIsoft PI Web API that is later than the 2018 version.
3
What products are affected by CVE-2019-13516?
CVE-2019-13516 affects OSIsoft PI Web API versions up to and including 2018.
4
What type of attack does CVE-2019-13516 expose the system to?
CVE-2019-13516 exposes the system to direct attacks due to inadequate cross-site request forgery protections.
5
Is there a workaround for CVE-2019-13516?
There are no documented workarounds available for CVE-2019-13516 other than applying the necessary updates.