SB2016070404 - Access control input validation flaw vulnerability in IBM WebSphere Commerce Developer
Published: July 4, 2016 Updated: July 4, 2016
Security Bulletin ID
SB2016070404
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Access control input validation flaw vulnerability (CVE-ID: CVE-2016-2863)
The vulnerability allows a remote attacker to conduct cross-site request forgery attacks.The vulnerability exists due to input validation error. A remote unauthenticated attacker can trick the victim to follow a specially crafted link and take actions on the target system as if being the target authenticated user.
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer are affected.
Successful exploitation of this vulnerability may result in modification of user information.
Remediation
Install update from vendor's website.