Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Portal | 8.5.0.0 |
| Ibm | Web Content Manager | All versions |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI62594
- http://www-01.ibm.com/support/docview.wss?uid=swg21983974Vendor Advisory
- http://www.securitytracker.com/id/1036143Third Party AdvisoryVDB Entry
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI62594
- http://www-01.ibm.com/support/docview.wss?uid=swg21983974Vendor Advisory
- http://www.securitytracker.com/id/1036143Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-2901?
CVE-2016-2901 is a vulnerability with a CVSS score of 8.8 (HIGH). Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authenti...
How severe is CVE-2016-2901?
CVE-2016-2901 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2901?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Websphere Portal, Ibm Web Content Manager.