Lucene search

K
cveIbmCVE-2015-2026
HistoryOct 04, 2015 - 2:59 a.m.

CVE-2015-2026

2015-10-0402:59:09
CWE-352
ibm
web.nvd.nist.gov
25
cve-2015-2026
cross-site request forgery
csrf
ibm websphere extreme scale
authentication hijacking
xss sequences
nvd

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

43.7%

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Affected configurations

Nvd
Node
ibmwebsphere_extreme_scaleMatch7.1.0
OR
ibmwebsphere_extreme_scaleMatch7.1.0.2
OR
ibmwebsphere_extreme_scaleMatch7.1.1
VendorProductVersionCPE
ibmwebsphere_extreme_scale7.1.0cpe:2.3:a:ibm:websphere_extreme_scale:7.1.0:*:*:*:*:*:*:*
ibmwebsphere_extreme_scale7.1.0.2cpe:2.3:a:ibm:websphere_extreme_scale:7.1.0.2:*:*:*:*:*:*:*
ibmwebsphere_extreme_scale7.1.1cpe:2.3:a:ibm:websphere_extreme_scale:7.1.1:*:*:*:*:*:*:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

43.7%

Related for CVE-2015-2026