Vulnerability Name: | CVE-2007-5799 (CCN-38179) | ||||||||
Assigned: | 2007-10-30 | ||||||||
Published: | 2007-10-30 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-5799 Source: OSVDB Type: UNKNOWN 41619 Source: CCN Type: SA27448 IBM WebSphere "uddigui/navigateTree.do" Cross-Site Scripting and Request Forgery Source: SECUNIA Type: Vendor Advisory 27448 Source: CCN Type: SECTRACK ID: 1018884 IBM WebSphere Application Server Input Validation Hole in `uddigui/navigateTree.do` Page Permits Cross-Site Scripting Attacks Source: AIXAPAR Type: UNKNOWN PK50245 Source: CCN Type: IBM APAR PK50245 VALIDATION NEEDED FOR PARAMETERS THAT ARE PASSED TO THE NAVIGATETREE.DO PAGE IN THE UDDI USER CONSOLE Source: CCN Type: OSVDB ID: 41619 IBM WebSphere uddigui/navigateTree.do Multiple Parameter CSRF Source: BID Type: UNKNOWN 26276 Source: CCN Type: BID-26276 IBM WebSphere Application Server UDDI Console Multiple Input Validation Vulnerabilities Source: SECTRACK Type: UNKNOWN 1018884 Source: XF Type: UNKNOWN websphere-navigatetree-csrf(38179) Source: XF Type: UNKNOWN websphere-navigatetree-csrf(38179) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |