CVE-2012-3294

medium
Published 2012-08-17 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File Transfer 7.5, allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add user accounts via the /wmqfteconsole/Filespaces URI, (2) modify permissions via the /wmqfteconsole/FileSpacePermisssions URI, or (3) add MQ Message Descriptor (MQMD) user accounts via the /wmqfteconsole/UploadUsers URI.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21607482

Application impact

VendorProductVersionsFixed
ibmwebsphere_mq{"endIncluding":"7.0.4"}
ibmwebsphere_mq7.0
ibmwebsphere_mq7.0.0.1
ibmwebsphere_mq7.0.1.0
ibmwebsphere_mq7.0.2.0
ibmwebsphere_mq7.0.2.2
ibmwebsphere_mq7.0.4.0
ibmwebsphere_mq_managed_file_transfer7.5

References

CWEs

CWE-352

Verify integrity in audit chain (admin only). AS-IS.