Cross-Site Request Forgery Vulnerability in IBM Tivoli Storage Manager for Virtual Environments
CVE-2016-6033

8.8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
15 February 2017

Summary

IBM Tivoli Storage Manager for Virtual Environments 7.1 is susceptible to a cross-site request forgery vulnerability that could allow attackers to initiate unauthorized actions by leveraging the trust of a legitimate user. This type of vulnerability can lead to serious security risks, enabling malicious activities without the user's consent. For detailed insights and mitigation strategies, refer to IBM's official documentation.

Affected Version(s)

Tivoli Storage Manager for Virtual Environments 6.3

Tivoli Storage Manager for Virtual Environments 6.4

Tivoli Storage Manager for Virtual Environments 7.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.