May 4, 2019 9:01 am EDT
Categorized: Medium Severity
Share this post:
A recent product security scanning exercise identified that a cross-site request forgery vulnerability exists within REST in IBM Cúram Social Program Management. The issue relates to the checking of the HTTP referrer header for GET requests on the server side, which should be checked in a similar way to all other requests. Note: If you are using the REST API, you are vulnerable to cross-site request forgery.
CVE(s): CVE-2018-2001
Affected product(s) and affected version(s):
IBM Cúram Social Program Management 7.0.5.0 – 7.0.5.0 IBM Cúram Social Program Management 7.0.0.0 – 7.0.4.0
IBM Cúram Social Program Management 6.2.0.0 – 6.2.0.6
IBM Cúram Social Program Management 6.1.0.0 – 6.1.1.6
Note: The REST API was not present in version 6.0.5 and earlier versions, so these versions are not vulnerable.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10883184
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/154891
from IBM Product Security Incident Response Team https://ibm.co/2LwyDOW
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.