Vulnerability Name: CVE-2013-0532 (CCN-82595) Assigned: 2012-12-16 Published: 2013-03-25 Updated: 2017-08-29 Summary: Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that cause a denial of service via malformed HTTP data. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-352 Vulnerability Consequences: Cross-Site Scripting References: Source: MITRE Type: CNACVE-2013-0532 Source: CCN Type: SA52764IBM Security AppScan Enterprise Multiple Vulnerabilities Source: CCN Type: SA52765IBM Rational Policy Tester Multiple Vulnerabilities Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21626264 Source: CCN Type: IBM Security Bulletin 1631304Multiple vulnerabilities in IBM Rational Policy Tester (CVE-2013-0532, CVE-2013-0512, CVE-2012-4431, CVE-2013-0513, CVE-2008-4033, CVE-2013-0474, CVE-2013-0473, CVE-2012-5081) Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21631304 Source: CCN Type: IBM Security Bulletin 1626264Multiple vulnerabilities in IBM Security AppScan Enterprise (CVE-2013-0532, CVE-2013-0510, CVE-2013-0512, CVE-2012-4431, CVE-2013-0513, CVE-2008-4033, CVE-2013-0474, CVE-2013-0511, CVE-2013-0473, CVE-2012-5081) Source: CCN Type: BID-58683Multiple IBM Products CVE-2013-0532 Cross Site Request Forgery Vulnerability Source: XF Type: UNKNOWNappscan-cve20130532-csrf(82595) Source: XF Type: UNKNOWNappscan-cve20130532-csrf(82595) Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:security_appscan:5.6.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.0.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.0.2:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.1.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.1.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.11:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.5.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.5.0.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.6.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.6.0.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.6.0.2:-:enterprise:*:*:*:*:* Configuration 2 :cpe:/a:ibm:rational_policy_tester:5.6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.3:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:ibm:rational_policy_tester:8.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_appscan:5.2:*:enterprise:*:*:*:*:* OR cpe:/a:ibm:rational_appscan:8.0.0:*:enterprise:*:*:*:*:* OR cpe:/a:ibm:rational_appscan:8.5.0:*:enterprise:*:*:*:*:* Denotes that component is vulnerable BACK
ibm security appscan 5.6.0.0 -
ibm security appscan 8.0.0.0 -
ibm security appscan 8.0.0.1 -
ibm security appscan 8.0.0.2 -
ibm security appscan 8.0.1.0 -
ibm security appscan 8.0.1.1 -
ibm security appscan 8.0.11 -
ibm security appscan 8.5.0.0 -
ibm security appscan 8.5.0.1 -
ibm security appscan 8.6.0.0 -
ibm security appscan 8.6.0.1 -
ibm security appscan 8.6.0.2 -
ibm rational policy tester 5.6.0.0
ibm rational policy tester 8.0.0.0
ibm rational policy tester 8.0.0.1
ibm rational policy tester 8.0.0.2
ibm rational policy tester 8.0.1.0
ibm rational policy tester 8.0.1.1
ibm rational policy tester 8.5.0.0
ibm rational policy tester 8.5.0.1
ibm rational policy tester 8.5.0.2
ibm rational policy tester 8.5.0.3
ibm rational policy tester 8.0.0.0
ibm rational appscan 5.2
ibm rational appscan 8.0.0
ibm rational appscan 8.5.0