CVE-2013-4057
Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0021 (0.2%)
Percentile: 43.3%
EPSS: 2026-05-06
Affects
ibm:infosphere_information_serverTechnical description
Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.
Published: 3/16/2014, 2:06:44 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR49200
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR49206
- http://www-01.ibm.com/support/docview.wss?uid=swg21666684
- http://www.securityfocus.com/bid/66154
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86546
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR48815
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR49200