Cross-Site Request Forgery in IBM Tivoli Storage Productivity Center
CVE-2016-8941

8.8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 February 2017

Summary

IBM Tivoli Storage Productivity Center is susceptible to a cross-site request forgery (CSRF) vulnerability. This security flaw could permit attackers to transmit malicious requests from a trusted user's session, potentially leading to unauthorized operations been performed on the platform. Successful exploitation of this vulnerability allows malicious actors to manipulate the functions of the application, posing significant risks to data integrity and system trust.

Affected Version(s)

Spectrum Control Standard Select Edition 5.1

Spectrum Control Standard Select Edition 5.1.1

Spectrum Control Standard Select Edition 5.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.