VYPR
Unrated severityNVD Advisory· Published Mar 16, 2014· Updated May 6, 2026

CVE-2013-4057

CVE-2013-4057

Description

Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.

Affected products

10
  • cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.7.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:9.1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:9.1.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.