Vulnerability Name: | CVE-2013-2980 (CCN-84113) | ||||||||
Assigned: | 2013-06-14 | ||||||||
Published: | 2013-06-14 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Cross-site request forgery (CSRF) vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to hijack the authentication of arbitrary users for requests that access monitored database information. | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-2980 Source: CCN Type: SA53840 IBM Data Studio Web Console Two Vulnerabilities Source: CCN Type: IBM Security Advisory 1638733 IBM Data Studio Web Console is vulnerable to cross-site request forgery, caused by improper validation of browser request headers Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21638733 Source: CCN Type: BID-60509 IBM Data Studio Web Console CVE-2013-2980 Cross Site Request Forgery Vulnerability Source: XF Type: UNKNOWN datastudio-cve20132980-csrf(84113) Source: XF Type: UNKNOWN datastudio-cve20132980-csrf(84113) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |