| Vulnerability Name: | CVE-2016-2863 (CCN-112749) | ||||||||||||
| Assigned: | 2016-06-28 | ||||||||||||
| Published: | 2016-06-28 | ||||||||||||
| Updated: | 2019-09-30 | ||||||||||||
| Summary: | Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | ||||||||||||
| CVSS v3 Severity: | 8.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) 7.0 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.0 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-352 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-2863 Source: AIXAPAR Type: UNKNOWN JR55776 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21983626 Source: CCN Type: IBM Security Bulletin 1983626 (WebSphere Commerce Enterprise) Cross-site Request Forgery (CSRF) security vulnerability in IBM WebSphere Commerce (CVE-2016-2863) Source: BID Type: UNKNOWN 91544 Source: CCN Type: BID-91544 IBM WebSphere Commerce CVE-2016-2863 Unspecified Cross Site Request Forgery Vulnerability Source: SECTRACK Type: UNKNOWN 1036219 Source: XF Type: UNKNOWN ibm-websphere-cve20162863-csrf(112749) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||