PT-2013-4075 · Ibm · Ibm Data Studio

Published

2013-06-17

·

Updated

2017-08-29

·

CVE-2013-2980

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Data Studio versions 3.1.0 through 3.1.1
Description A cross-site request forgery issue in the Web Console allows remote attackers to hijack user authentication for requests accessing monitored database information.
Recommendations For IBM Data Studio versions 3.1.0 through 3.1.1, consider disabling access to the Web Console until a patch is available to prevent exploitation of the CSRF issue.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2980

Affected Products

Ibm Data Studio