Vulnerability index

Browse CVEs

199 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Bigfix Remote Control HIGH 8.8
CVE-2016-2963

Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arb…

Fix: after 9.1.2
Fix from $1,950 2016-11-30
Connections HIGH 8.8
CVE-2016-3007

Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticate…

Patch available
Fix from $1,950 2016-09-26
Jazz Reporting Service HIGH 8.8
CVE-2016-2889

Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x bef…

Mitigation only
Fix from $1,950 2016-07-08
Websphere Commerce HIGH 8.0
CVE-2016-2863

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.2 all…

Mitigation only
Fix from $1,950 2016-07-03
Tririga Application Platform HIGH 8.0
CVE-2016-0386

Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 al…

Mitigation only
Fix from $1,950 2016-07-02
Websphere Portal HIGH 8.8
CVE-2016-2901

Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Man…

Mitigation only
Fix from $1,950 2016-06-26
Flashsystem V9000 Firmware HIGH 8.8
CVE-2015-7446

Cross-site request forgery (CSRF) vulnerability in IBM Flash System V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4 allows remot…

Mitigation only
Fix from $1,950 2016-03-12
Emptoris Contract Management HIGH 8.8
CVE-2015-5050

Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.…

Mitigation only
Fix from $1,950 2016-02-15
Websphere Commerce HIGH 8.8
CVE-2015-5007

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows re…

Mitigation only
Fix from $1,950 2016-01-15
Jazz Reporting Service HIGH 8.8
CVE-2015-7465

Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifi…

Mitigation only
Fix from $1,950 2016-01-10
Connections MEDIUM 5.4
CVE-2015-5037

Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows …

Fix: after 3.0.1.1
Fix from $1,600 2016-01-03
Mashups Center HIGH 8.8
CVE-2015-7407

Cross-site request forgery (CSRF) vulnerability in Lotus Mashups in IBM Mashup Center 3.0.0.1 allows remote attackers to hijack the authentication of…

Mitigation only
Fix from $1,950 2016-01-02
Security Qradar Incident Forensics MEDIUM 6.8
CVE-2015-1997

Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar Vulnerability Manager 7.2.x before 7.2.5 Patch 5 allows remote attackers to hi…

Mitigation only
Fix from $1,600 2015-11-08
Websphere Extreme Scale MEDIUM 6.0
CVE-2015-2026

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authentica…

Patch available
Fix from $1,600 2015-10-04
Openpages Grc Platform MEDIUM 6.8
CVE-2015-0145

Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 befor…

Patch available
Fix from $1,600 2015-10-03
Leads MEDIUM 6.0
CVE-2015-0115

Cross-site request forgery (CSRF) vulnerability in IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 t…

Patch available
Fix from $1,600 2015-06-28
Security Network Protection Firmware MEDIUM 6.8
CVE-2014-6198

Cross-site request forgery (CSRF) vulnerability in IBM Security Network Protection 5.3 before 5.3.1 allows remote attackers to hijack the authenticat…

Patch available
Fix from $1,600 2015-06-28
Endpoint Manager Family MEDIUM 6.8
CVE-2014-4774

Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use A…

Mitigation only
Fix from $1,600 2015-05-25
Optim Workload Replay MEDIUM 6.8
CVE-2015-1894

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 allows remote attackers to hijack the auth…

Patch available
Fix from $1,600 2015-05-25
Curam Social Program Management MEDIUM 6.8
CVE-2014-6090

Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorComman…

Patch available
Fix from $1,600 2015-04-27
Rational Clearquest MEDIUM 6.8
CVE-2014-8925

Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.…

Patch available
Fix from $1,600 2015-03-25
Websphere Portal MEDIUM 6.8
CVE-2014-6214

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote attackers to h…

Patch available
Fix from $1,600 2015-03-13
Security Identity Manager MEDIUM 6.0
CVE-2014-6168

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hija…

Mitigation only
Fix from $1,600 2014-12-29
Websphere Service Registry And Repository MEDIUM 6.0
CVE-2014-6187

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x before…

Mitigation only
Fix from $1,600 2014-12-24
Security Access Manager For Web MEDIUM 6.8
CVE-2014-6077

Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x be…

Mitigation only
Fix from $1,600 2014-12-18
Websphere Datapower Xc10 Appliance Firmware MEDIUM 6.0
CVE-2014-3058

Cross-site request forgery (CSRF) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated user…

Mitigation only
Fix from $1,600 2014-12-11
Qradar Vulnerability Manager MEDIUM 6.8
CVE-2014-4829

Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch…

Patch available
Fix from $1,600 2014-11-28
Tririga Application Platform MEDIUM 6.0
CVE-2014-4839

Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.…

Mitigation only
Fix from $1,600 2014-10-29
Websphere Portal MEDIUM 6.8
CVE-2014-6125

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arb…

Patch available
Fix from $1,600 2014-10-28
Websphere Application Server MEDIUM 6.0
CVE-2014-4816

Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 bef…

Patch available
Fix from $1,600 2014-09-23