Lucene search

K
cveMitreCVE-2010-3271
HistoryJul 18, 2011 - 10:55 p.m.

CVE-2010-3271

2011-07-1822:55:00
CWE-352
mitre
web.nvd.nist.gov
30
ibm
websphere
app server
csrf
vulnerability
cve-2010-3271

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.004

Percentile

75.1%

Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.

Affected configurations

Nvd
Node
ibmwebsphere_application_serverRange7.0.0.13
OR
ibmwebsphere_application_serverMatch2.0
OR
ibmwebsphere_application_serverMatch3.0
OR
ibmwebsphere_application_serverMatch3.0.2
OR
ibmwebsphere_application_serverMatch3.0.2.1
OR
ibmwebsphere_application_serverMatch3.0.2.2
OR
ibmwebsphere_application_serverMatch3.0.2.3
OR
ibmwebsphere_application_serverMatch3.0.2.4
OR
ibmwebsphere_application_serverMatch3.0.21
OR
ibmwebsphere_application_serverMatch3.5
OR
ibmwebsphere_application_serverMatch3.5.1
OR
ibmwebsphere_application_serverMatch3.5.2
OR
ibmwebsphere_application_serverMatch3.5.3
OR
ibmwebsphere_application_serverMatch3.52
OR
ibmwebsphere_application_serverMatch4.0.1
OR
ibmwebsphere_application_serverMatch4.0.2
OR
ibmwebsphere_application_serverMatch4.0.3
OR
ibmwebsphere_application_serverMatch4.0.4
OR
ibmwebsphere_application_serverMatch5.0
OR
ibmwebsphere_application_serverMatch5.0.0
OR
ibmwebsphere_application_serverMatch5.0.1
OR
ibmwebsphere_application_serverMatch5.0.2
OR
ibmwebsphere_application_serverMatch5.0.2.1
OR
ibmwebsphere_application_serverMatch5.0.2.2
OR
ibmwebsphere_application_serverMatch5.0.2.3
OR
ibmwebsphere_application_serverMatch5.0.2.4
OR
ibmwebsphere_application_serverMatch5.0.2.5
OR
ibmwebsphere_application_serverMatch5.0.2.6
OR
ibmwebsphere_application_serverMatch5.0.2.7
OR
ibmwebsphere_application_serverMatch5.0.2.8
OR
ibmwebsphere_application_serverMatch5.0.2.9
OR
ibmwebsphere_application_serverMatch5.0.2.10
OR
ibmwebsphere_application_serverMatch5.0.2.11
OR
ibmwebsphere_application_serverMatch5.0.2.12
OR
ibmwebsphere_application_serverMatch5.0.2.13
OR
ibmwebsphere_application_serverMatch5.0.2.14
OR
ibmwebsphere_application_serverMatch5.0.2.15
OR
ibmwebsphere_application_serverMatch5.0.2.16
OR
ibmwebsphere_application_serverMatch5.1.0
OR
ibmwebsphere_application_serverMatch5.1.0.2
OR
ibmwebsphere_application_serverMatch5.1.0.3
OR
ibmwebsphere_application_serverMatch5.1.0.4
OR
ibmwebsphere_application_serverMatch5.1.0.5
OR
ibmwebsphere_application_serverMatch5.1.1
OR
ibmwebsphere_application_serverMatch5.1.1.1
OR
ibmwebsphere_application_serverMatch5.1.1.2
OR
ibmwebsphere_application_serverMatch5.1.1.3
OR
ibmwebsphere_application_serverMatch5.1.1.4
OR
ibmwebsphere_application_serverMatch5.1.1.5
OR
ibmwebsphere_application_serverMatch5.1.1.6
OR
ibmwebsphere_application_serverMatch5.1.1.7
OR
ibmwebsphere_application_serverMatch5.1.1.8
OR
ibmwebsphere_application_serverMatch5.1.1.9
OR
ibmwebsphere_application_serverMatch5.1.1.10
OR
ibmwebsphere_application_serverMatch5.1.1.11
OR
ibmwebsphere_application_serverMatch5.1.1.12
OR
ibmwebsphere_application_serverMatch5.1.1.13
OR
ibmwebsphere_application_serverMatch5.1.1.14
OR
ibmwebsphere_application_serverMatch5.1.1.15
OR
ibmwebsphere_application_serverMatch5.1.1.16
OR
ibmwebsphere_application_serverMatch5.1.1.17
OR
ibmwebsphere_application_serverMatch6.0
OR
ibmwebsphere_application_serverMatch6.0.0.1
OR
ibmwebsphere_application_serverMatch6.0.0.2
OR
ibmwebsphere_application_serverMatch6.0.0.3
OR
ibmwebsphere_application_serverMatch6.0.1
OR
ibmwebsphere_application_serverMatch6.0.1.1
OR
ibmwebsphere_application_serverMatch6.0.1.2
OR
ibmwebsphere_application_serverMatch6.0.1.3
OR
ibmwebsphere_application_serverMatch6.0.1.5
OR
ibmwebsphere_application_serverMatch6.0.1.7
OR
ibmwebsphere_application_serverMatch6.0.1.9
OR
ibmwebsphere_application_serverMatch6.0.1.11
OR
ibmwebsphere_application_serverMatch6.0.1.13
OR
ibmwebsphere_application_serverMatch6.0.1.15
OR
ibmwebsphere_application_serverMatch6.0.1.17
OR
ibmwebsphere_application_serverMatch6.0.2
OR
ibmwebsphere_application_serverMatch6.0.2.1
OR
ibmwebsphere_application_serverMatch6.0.2.2
OR
ibmwebsphere_application_serverMatch6.0.2.3
OR
ibmwebsphere_application_serverMatch6.0.2.4
OR
ibmwebsphere_application_serverMatch6.0.2.5
OR
ibmwebsphere_application_serverMatch6.0.2.6
OR
ibmwebsphere_application_serverMatch6.0.2.7
OR
ibmwebsphere_application_serverMatch6.0.2.9
OR
ibmwebsphere_application_serverMatch6.0.2.11
OR
ibmwebsphere_application_serverMatch6.0.2.13
OR
ibmwebsphere_application_serverMatch6.0.2.15
OR
ibmwebsphere_application_serverMatch6.0.2.17
OR
ibmwebsphere_application_serverMatch6.0.2.19
OR
ibmwebsphere_application_serverMatch6.0.2.22
OR
ibmwebsphere_application_serverMatch6.0.2.23
OR
ibmwebsphere_application_serverMatch6.0.2.24
OR
ibmwebsphere_application_serverMatch6.0.2.25
OR
ibmwebsphere_application_serverMatch6.0.2.27
OR
ibmwebsphere_application_serverMatch6.0.2.28
OR
ibmwebsphere_application_serverMatch6.0.2.29
OR
ibmwebsphere_application_serverMatch6.0.2.30
OR
ibmwebsphere_application_serverMatch6.0.2.31
OR
ibmwebsphere_application_serverMatch6.0.2.32
OR
ibmwebsphere_application_serverMatch6.1
OR
ibmwebsphere_application_serverMatch6.1.0
OR
ibmwebsphere_application_serverMatch6.1.0.0
OR
ibmwebsphere_application_serverMatch6.1.0.1
OR
ibmwebsphere_application_serverMatch6.1.0.2
OR
ibmwebsphere_application_serverMatch6.1.0.3
OR
ibmwebsphere_application_serverMatch6.1.0.5
OR
ibmwebsphere_application_serverMatch6.1.0.7
OR
ibmwebsphere_application_serverMatch6.1.0.9
OR
ibmwebsphere_application_serverMatch6.1.0.11
OR
ibmwebsphere_application_serverMatch6.1.0.12
OR
ibmwebsphere_application_serverMatch6.1.0.15
OR
ibmwebsphere_application_serverMatch6.1.0.17
OR
ibmwebsphere_application_serverMatch6.1.0.19
OR
ibmwebsphere_application_serverMatch6.1.0.21
OR
ibmwebsphere_application_serverMatch6.1.0.23
OR
ibmwebsphere_application_serverMatch6.1.0.25
OR
ibmwebsphere_application_serverMatch6.1.0.27
OR
ibmwebsphere_application_serverMatch6.1.0.29
OR
ibmwebsphere_application_serverMatch6.1.0.31
OR
ibmwebsphere_application_serverMatch6.1.0.33
OR
ibmwebsphere_application_serverMatch6.1.1
OR
ibmwebsphere_application_serverMatch6.1.3
OR
ibmwebsphere_application_serverMatch6.1.5
OR
ibmwebsphere_application_serverMatch6.1.6
OR
ibmwebsphere_application_serverMatch6.1.7
OR
ibmwebsphere_application_serverMatch6.1.13
OR
ibmwebsphere_application_serverMatch6.1.14
OR
ibmwebsphere_application_serverMatch7.0
OR
ibmwebsphere_application_serverMatch7.0.0.1
OR
ibmwebsphere_application_serverMatch7.0.0.2
OR
ibmwebsphere_application_serverMatch7.0.0.3
OR
ibmwebsphere_application_serverMatch7.0.0.4
OR
ibmwebsphere_application_serverMatch7.0.0.5
OR
ibmwebsphere_application_serverMatch7.0.0.6
OR
ibmwebsphere_application_serverMatch7.0.0.7
OR
ibmwebsphere_application_serverMatch7.0.0.8
OR
ibmwebsphere_application_serverMatch7.0.0.9
OR
ibmwebsphere_application_serverMatch7.0.0.11
VendorProductVersionCPE
ibmwebsphere_application_server*cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
ibmwebsphere_application_server2.0cpe:2.3:a:ibm:websphere_application_server:2.0:*:*:*:*:*:*:*
ibmwebsphere_application_server3.0cpe:2.3:a:ibm:websphere_application_server:3.0:*:*:*:*:*:*:*
ibmwebsphere_application_server3.0.2cpe:2.3:a:ibm:websphere_application_server:3.0.2:*:*:*:*:*:*:*
ibmwebsphere_application_server3.0.2.1cpe:2.3:a:ibm:websphere_application_server:3.0.2.1:*:*:*:*:*:*:*
ibmwebsphere_application_server3.0.2.2cpe:2.3:a:ibm:websphere_application_server:3.0.2.2:*:*:*:*:*:*:*
ibmwebsphere_application_server3.0.2.3cpe:2.3:a:ibm:websphere_application_server:3.0.2.3:*:*:*:*:*:*:*
ibmwebsphere_application_server3.0.2.4cpe:2.3:a:ibm:websphere_application_server:3.0.2.4:*:*:*:*:*:*:*
ibmwebsphere_application_server3.0.21cpe:2.3:a:ibm:websphere_application_server:3.0.21:*:*:*:*:*:*:*
ibmwebsphere_application_server3.5cpe:2.3:a:ibm:websphere_application_server:3.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 1391

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.004

Percentile

75.1%