CVE-2013-0460: IBM WebSphere Application Server
Medium severity, CVSS 6.8. EPSS: 1% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 and 7.0 before 7.0.0.27 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
Affected products
- IBM WebSphere Application Server: version 6.1.0.0 only; version 6.1.0.1 only; version 6.1.0.2 only; version 6.1.0.3 only; version 6.1.0.5 only; version 6.1.0.7 only; …
Published 2013-01-27. Last modified 2026-06-16.