Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that cause a denial of service via malformed HTTP data.
2013-03-29T16:09:03.893
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | security_appscan | 5.6.0.0 | Yes |
Application | ibm | security_appscan | 8.0.0.0 | Yes |
Application | ibm | security_appscan | 8.0.0.1 | Yes |
Application | ibm | security_appscan | 8.0.0.2 | Yes |
Application | ibm | security_appscan | 8.0.1.0 | Yes |
Application | ibm | security_appscan | 8.0.1.1 | Yes |
Application | ibm | security_appscan | 8.0.11 | Yes |
Application | ibm | security_appscan | 8.5.0.0 | Yes |
Application | ibm | security_appscan | 8.5.0.1 | Yes |
Application | ibm | security_appscan | 8.6.0.0 | Yes |
Application | ibm | security_appscan | 8.6.0.1 | Yes |
Application | ibm | security_appscan | 8.6.0.2 | Yes |
Application | ibm | rational_policy_tester | 5.6.0.0 | Yes |
Application | ibm | rational_policy_tester | 8.0.0.0 | Yes |
Application | ibm | rational_policy_tester | 8.0.0.1 | Yes |
Application | ibm | rational_policy_tester | 8.0.0.2 | Yes |
Application | ibm | rational_policy_tester | 8.0.1.0 | Yes |
Application | ibm | rational_policy_tester | 8.0.1.1 | Yes |
Application | ibm | rational_policy_tester | 8.5.0.0 | Yes |
Application | ibm | rational_policy_tester | 8.5.0.1 | Yes |
Application | ibm | rational_policy_tester | 8.5.0.2 | Yes |
Application | ibm | rational_policy_tester | 8.5.0.3 | Yes |