CVE-2013-4000Cross-Site Request Forgery in IBM Cognos Command Center

Severity
6.8MEDIUMNVD
EPSS
0.1%
top 71.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 14
Latest updateMay 17

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-6hg5-jqvr-2wj8: Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 102022-05-17
Kernel
pipe: limit the per-user amount of pages allocated in pipes2016-01-18
CVEList
CVE-2013-4000: Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 102013-12-14

📋Vendor Advisories

2
Cisco
Cisco Nexus 4000 Series Switches IPv6 Denial of Service Vulnerability2013-11-13
Cisco
Cisco Video Surveillance 4000 Series IP Camera Default Credential Vulnerability2013-10-15
CVE-2013-4000 — Cross-Site Request Forgery in IBM | cvebase