MEDIUM · 4.9

CVE-2013-0580

Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to hijack the ...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS Score

4.9

MEDIUM

AV:A/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
IbmInfosphere Optim Data Growth For Oracle E-Business Suite6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-0580?

CVE-2013-0580 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to hijack the ...

How severe is CVE-2013-0580?

CVE-2013-0580 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-0580?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Infosphere Optim Data Growth For Oracle E-Business Suite.