Cross-Site Request Forgery Vulnerability in IBM Tivoli Endpoint Manager
CVE-2013-0452
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 29 March 2013
Summary
The Software Use Analysis application in IBM Tivoli Endpoint Manager versions prior to 1.3.3 is susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw allows remote attackers to potentially hijack the authentication sessions of arbitrary users. Attackers can exploit this vulnerability by crafting a malicious website that sends specific Flash Action Message Format (AMF) messages. Victims who visit the site could unknowingly authenticate against the vulnerable application, leading to unauthorized access and manipulation of user data.
References
Timeline
Vulnerability published
Vulnerability Reserved