Cross-Site Request Forgery in IBM Tivoli Storage Productivity Center
CVE-2016-8941
8.8HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 1 February 2017
Summary
IBM Tivoli Storage Productivity Center is susceptible to a cross-site request forgery (CSRF) vulnerability. This security flaw could permit attackers to transmit malicious requests from a trusted user's session, potentially leading to unauthorized operations been performed on the platform. Successful exploitation of this vulnerability allows malicious actors to manipulate the functions of the application, posing significant risks to data integrity and system trust.
Affected Version(s)
Spectrum Control Standard Select Edition 5.1
Spectrum Control Standard Select Edition 5.1.1
Spectrum Control Standard Select Edition 5.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved