Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, and WebSphere MQ - Managed File Transfer 7.5, allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add user accounts via the /wmqfteconsole/Filespaces URI, (2) modify permissions via the /wmqfteconsole/FileSpacePermisssions URI, or (3) add MQ Message Descriptor (MQMD) user accounts via the /wmqfteconsole/UploadUsers URI.
2012-08-17T10:31:52.090
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | websphere_mq | ≤ 7.0.4 | Yes |
Application | ibm | websphere_mq | 7.0 | Yes |
Application | ibm | websphere_mq | 7.0.0.1 | Yes |
Application | ibm | websphere_mq | 7.0.1.0 | Yes |
Application | ibm | websphere_mq | 7.0.2.0 | Yes |
Application | ibm | websphere_mq | 7.0.2.2 | Yes |
Application | ibm | websphere_mq | 7.0.4.0 | Yes |
Application | ibm | websphere_mq_managed_file_transfer | 7.5 | Yes |