CVE-2016-3009
low
CVSS v3
3.5
CVSS v2
3.5
VIR risk
3.5
Description
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page.
Predictions
Exploit likelihood
45%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21990864
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | connections | 4.0.0.0 | |
| ibm | connections | 4.5.0.0 | |
| ibm | connections | 5.0.0.0 | |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO90039
- http://www-01.ibm.com/support/docview.wss?uid=swg21990864
- http://www.securityfocus.com/bid/94329
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO90039
- http://www-01.ibm.com/support/docview.wss?uid=swg21990864
- http://www.securityfocus.com/bid/94329
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.