Cross-Site Request Forgery Vulnerability in IBM Tivoli Endpoint Manager
CVE-2013-0452

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
29 March 2013

Summary

The Software Use Analysis application in IBM Tivoli Endpoint Manager versions prior to 1.3.3 is susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw allows remote attackers to potentially hijack the authentication sessions of arbitrary users. Attackers can exploit this vulnerability by crafting a malicious website that sends specific Flash Action Message Format (AMF) messages. Victims who visit the site could unknowingly authenticate against the vulnerable application, leading to unauthorized access and manipulation of user data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.