CVE-2015-5007
published 2016-01-15CVE-2015-5007: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows remote…
PriorityP434high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.91%
55.9th percentile
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5007 springframework: spring: Path matching inconsistency [fedora-all]
bugzilla·2016-07-08·CVSS 8.8
CVE-2016-5007 [HIGH] CVE-2016-5007 springframework: spring: Path matching inconsistency [fedora-all]
CVE-2016-5007 springframework: spring: Path matching inconsistency [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2016-5007 springframework-security: spring: Path matching inconsistency [fedora-all]
bugzilla·2016-07-08·CVSS 8.8
CVE-2016-5007 [HIGH] CVE-2016-5007 springframework-security: spring: Path matching inconsistency [fedora-all]
CVE-2016-5007 springframework-security: spring: Path matching inconsistency [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2016-5007 spring: Path matching inconsistency
bugzilla·2016-07-08·CVSS 8.8
CVE-2016-5007 [HIGH] CVE-2016-5007 spring: Path matching inconsistency
CVE-2016-5007 spring: Path matching inconsistency
Both Spring Security and the Spring Framework rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. It was found that differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path segments, can lead Spring Security to not recognize certain paths as not protected that are in fact mapped to Spring MVC controllers that should be protected.
Affected versions:
Spring Security 3.2.x, 4.0.x, 4.1.0
Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x
Other unsupported versions are also affected
Upstream patches:
https://github.com/spring-projects/spring-framework/commit/a30ab3
https://github.com/spring-projects/spring-security/commit/e4c13e
Upstream b
http://www-01.ibm.com/support/docview.wss?uid=swg1JR54267http://www-01.ibm.com/support/docview.wss?uid=swg1JR54268http://www-01.ibm.com/support/docview.wss?uid=swg21972611http://www.securitytracker.com/id/1034639http://www-01.ibm.com/support/docview.wss?uid=swg1JR54267http://www-01.ibm.com/support/docview.wss?uid=swg1JR54268http://www-01.ibm.com/support/docview.wss?uid=swg21972611http://www.securitytracker.com/id/1034639
2016-01-15
Published