CVE-2012-3309
29.08.2012, 22:55
Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (aka csrf_status) feature is disabled, allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
| Vendor | Product | Version |
|---|---|---|
| ibm | infosphere_guardium | 𝑥 ≤ 8.2 |
| ibm | infosphere_guardium | 8.00 |
| ibm | infosphere_guardium | 8.01 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References