PT-2016-4162 · Ibm · Ibm Tririga Application Platform

Oktawian Powazka

·

Publicado

2016-07-01

·

Atualizado

2016-08-11

·

CVE-2016-0362

CVSS v3.1

7.7

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM TRIRIGA Application Platform versions 3.3 before 3.3.2.6 IBM TRIRIGA Application Platform versions 3.4 before 3.4.2.4 IBM TRIRIGA Application Platform versions 3.5 before 3.5.0.2
Description The issue allows remote authenticated users to conduct server-side request forgery (SSRF) attacks. This can trigger network traffic to arbitrary intranet or Internet hosts via a crafted proxy request to a web service.
Recommendations For versions 3.3 before 3.3.2.6, update to version 3.3.2.6 or later. For versions 3.4 before 3.4.2.4, update to version 3.4.2.4 or later. For versions 3.5 before 3.5.0.2, update to version 3.5.0.2 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2016-0362

Produtos afetados

Ibm Tririga Application Platform