VulnerabilityModified
CVE-2016-0377
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via…
MEDIUM 4.3EPSS 1.54%
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI56917Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21980645Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92514
- http://www.securitytracker.com/id/1036653
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI56917Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21980645Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92514
- http://www.securitytracker.com/id/1036653
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.