Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2016-0355 Cross-Site Request Forgery (CSRF) vulnerability in IBM Sametime
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery.
network
low complexity
ibm CWE-352
6.5
2017-08-29 CVE-2017-11455 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens.
network
low complexity
pulsesecure ivanti CWE-352
8.8
2017-08-29 CVE-2015-3655 Cross-Site Request Forgery (CSRF) vulnerability in Arubanetworks Clearpass
Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to hijack the authentication of administrators by leveraging improper enforcement of the anti-CSRF token.
network
low complexity
arubanetworks CWE-352
8.8
2017-08-28 CVE-2014-8900 Cross-Site Request Forgery (CSRF) vulnerability in IBM Urbancode Deploy
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
network
low complexity
ibm CWE-352
8.8
2017-08-25 CVE-2017-7926 Cross-Site Request Forgery (CSRF) vulnerability in Osisoft PI web API 1.8
A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0).
network
low complexity
osisoft CWE-352
8.8
2017-08-25 CVE-2017-12703 Cross-Site Request Forgery (CSRF) vulnerability in Westermo products
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0.
network
low complexity
westermo CWE-352
8.8
2017-08-23 CVE-2017-12970 Cross-Site Request Forgery (CSRF) vulnerability in Apache2Triad 1.5.4
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.
network
low complexity
apache2triad CWE-352
8.8
2017-08-22 CVE-2015-5258 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.
network
low complexity
fedoraproject vmware CWE-352
8.8
2017-08-22 CVE-2017-7557 Cross-Site Request Forgery (CSRF) vulnerability in Powerdns Dnsdist 1.1.0
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
network
low complexity
powerdns CWE-352
8.8
2017-08-21 CVE-2017-7423 Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Enterprise Developer and Enterprise Server
A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to forge requests, if this component is configured.
network
low complexity
microfocus CWE-352
8.8