CVE-2015-2026
published 2015-10-04CVE-2015-2026: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users…
PriorityP422medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
0.54%
41.6th percentile
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_extreme_scale | — | — |
| ibm | websphere_extreme_scale | — | — |
| ibm | websphere_extreme_scale | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7753-jvjf-pfjp: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7
ghsa_unreviewed·2022-05-17
CVE-2015-2026 [MEDIUM] CWE-352 GHSA-7753-jvjf-pfjp: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Citrix
Citrix Security Bulletin CTX220112
vendor_citrix·CVSS 7.5
CVE-2015-7704 [HIGH] Citrix Security Bulletin CTX220112
Citrix Security Bulletin CTX220112
CVE References: CVE-2015-7704, CVE-2015-7705, CVE-2017-5572, CVE-2017-5573, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX200378
vendor_citrix·CVSS 5.9
CVE-2015-3642 [MEDIUM] Citrix Security Bulletin CTX200378
Citrix Security Bulletin CTX200378
CVE References: CVE-2015-3642, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX200584
vendor_citrix·CVSS 5.0
CVE-2015-2682 [MEDIUM] Citrix Security Bulletin CTX200584
Citrix Security Bulletin CTX200584
CVE References: CVE-2015-2682, CVE-2015-2683, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1PI44098http://www-01.ibm.com/support/docview.wss?uid=swg1PI44105http://www-01.ibm.com/support/docview.wss?uid=swg21966044http://www-01.ibm.com/support/docview.wss?uid=swg1PI44098http://www-01.ibm.com/support/docview.wss?uid=swg1PI44105http://www-01.ibm.com/support/docview.wss?uid=swg21966044
2015-10-04
Published