← Back

CVE-2010-3271

nvd nist
Published: Jul 18, 2011Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.

Affected (139)

1 product
Websphere Application Server
Configuration A
139 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Up to 7.0.0.13
Version 2.0
Version 3.0.2.1
Version 3.0.2.2
Version 3.0.2.3
Version 3.0.2.4
Version 3.0.21
Version 3.0.2
Version 3.0
Version 3.5.1
Version 3.5.2
Version 3.5.3
Version 3.52
Version 3.5
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 5.0.0
Version 5.0.1
Version 5.0.2.10
Version 5.0.2.11
Version 5.0.2.12
Version 5.0.2.13
Version 5.0.2.14
Version 5.0.2.15
Version 5.0.2.16
Version 5.0.2.1
Version 5.0.2.2
Version 5.0.2.3
Version 5.0.2.4
Version 5.0.2.5
Version 5.0.2.6
Version 5.0.2.7
Version 5.0.2.8
Version 5.0.2.9
Version 5.0.2
Version 5.0
Version 5.1.0.2
Version 5.1.0.3
Version 5.1.0.4
Version 5.1.0.5
Version 5.1.0
Version 5.1.1.10
Version 5.1.1.11
Version 5.1.1.12
Version 5.1.1.13
Version 5.1.1.14
Version 5.1.1.15
Version 5.1.1.16
Version 5.1.1.17
Version 5.1.1.1
Version 5.1.1.2
Version 5.1.1.3
Version 5.1.1.4
Version 5.1.1.5
Version 5.1.1.6
Version 5.1.1.7
Version 5.1.1.8
Version 5.1.1.9
Version 5.1.1
Version 6.0.0.1
Version 6.0.0.2
Version 6.0.0.3
Version 6.0.1.11
Version 6.0.1.13
Version 6.0.1.15
Version 6.0.1.17
Version 6.0.1.1
Version 6.0.1.2
Version 6.0.1.3
Version 6.0.1.5
Version 6.0.1.7
Version 6.0.1.9
Version 6.0.1
Version 6.0.2.11
Version 6.0.2.13
Version 6.0.2.15
Version 6.0.2.17
Version 6.0.2.19
Version 6.0.2.1
Version 6.0.2.22
Version 6.0.2.23
Version 6.0.2.24
Version 6.0.2.25
Version 6.0.2.27
Version 6.0.2.28
Version 6.0.2.29
Version 6.0.2.2
Version 6.0.2.30
Version 6.0.2.31
Version 6.0.2.32
Version 6.0.2.3
Version 6.0.2.4
Version 6.0.2.5
Version 6.0.2.6
Version 6.0.2.7
Version 6.0.2.9
Version 6.0.2
Version 6.0
Version 6.1.0.0
Version 6.1.0.11
Version 6.1.0.12
Version 6.1.0.15
Version 6.1.0.17
Version 6.1.0.19
Version 6.1.0.1
Version 6.1.0.21
Version 6.1.0.23
Version 6.1.0.25
Version 6.1.0.27
Version 6.1.0.29
Version 6.1.0.2
Version 6.1.0.31
Version 6.1.0.33
Version 6.1.0.3
Version 6.1.0.5
Version 6.1.0.7
Version 6.1.0.9
Version 6.1.0
Version 6.1.13
Version 6.1.14
Version 6.1.1
Version 6.1.3
Version 6.1.5
Version 6.1.6
Version 6.1.7
Version 6.1
Version 7.0.0.11
Version 7.0.0.1
Version 7.0.0.2
Version 7.0.0.3
Version 7.0.0.4
Version 7.0.0.5
Version 7.0.0.6
Version 7.0.0.7
Version 7.0.0.8
Version 7.0.0.9
Version 7.0

References (10)

Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.