![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2010-3271 |
Description: | Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.902610 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-3271 BugTraq ID: 48305 http://www.securityfocus.com/bid/48305 Bugtraq: 20110615 CORE-2010-1021: IBM WebSphere Application Server Cross-Site Request Forgery (Google Search) http://www.securityfocus.com/archive/1/518465/100/0/threaded http://www.exploit-db.com/exploits/17404 http://www.coresecurity.com/content/IBM-WebSphere-CSRF http://securityreason.com/securityalert/8281 |