CVE-2013-4000

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cognos_command_center:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cognos_command_center:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:54

Type Values Removed Values Added
References () http://www-01.ibm.com/support/docview.wss?uid=swg21657932 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21657932 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/85150 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/85150 -

Information

Published : 2013-12-14 22:55

Updated : 2024-11-21 01:54


NVD link : CVE-2013-4000

Mitre link : CVE-2013-4000

CVE.ORG link : CVE-2013-4000


JSON object : View

Products Affected

ibm

  • cognos_command_center
CWE
CWE-352

Cross-Site Request Forgery (CSRF)