PDA

View Full Version : IBM WebSphere Application Server Cross Site Request Forgery


Java-monitor RSS bot
16-06-2011, 12:32
Core Security Technologies Advisory - The administrative console of IBM WebSphere Application Server is vulnerable to Cross-Site Request Forgery (CSRF) attacks, which can be exploited by remote attackers to force a logged-in administrator to perform unwanted actions on the IBM WebSphere administrative console, by enticing him to visit a malicious web page. Versions 7.0.0.11 and 7.0.0.13 are confirmed vulnerable.

More... (http://packetstormsecurity.org/files/view/102340/CORE-2010-1021.txt)