Cross-Site Request Forgery Vulnerability in IBM Tivoli Storage Manager for Virtual Environments
CVE-2016-6033
8.8HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 15 February 2017
Summary
IBM Tivoli Storage Manager for Virtual Environments 7.1 is susceptible to a cross-site request forgery vulnerability that could allow attackers to initiate unauthorized actions by leveraging the trust of a legitimate user. This type of vulnerability can lead to serious security risks, enabling malicious activities without the user's consent. For detailed insights and mitigation strategies, refer to IBM's official documentation.
Affected Version(s)
Tivoli Storage Manager for Virtual Environments 6.3
Tivoli Storage Manager for Virtual Environments 6.4
Tivoli Storage Manager for Virtual Environments 7.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved