SB2016070404 - Access control input validation flaw vulnerability in IBM WebSphere Commerce Developer



SB2016070404 - Access control input validation flaw vulnerability in IBM WebSphere Commerce Developer

Published: July 4, 2016 Updated: July 4, 2016

Security Bulletin ID SB2016070404
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Access control input validation flaw vulnerability (CVE-ID: CVE-2016-2863)

The vulnerability allows a remote attacker to conduct cross-site request forgery attacks.

The vulnerability exists due to input validation error. A remote unauthenticated attacker can trick the victim to follow a specially crafted link and take actions on the target system as if being the target authenticated user.

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer are affected.


Successful exploitation of this vulnerability may result in modification of user information.

Remediation

Install update from vendor's website.