Cross-Site Request Forgery Vulnerability in IBM Emptoris Services Procurement
CVE-2017-1442

8.8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
30 August 2017

Summary

The IBM Emptoris Services Procurement version 10.0.0.5 is susceptible to a cross-site request forgery (CSRF) attack, which could allow malicious entities to exploit the trust established between the user and the website. This vulnerability may enable attackers to perform unauthorized actions with the privileges of a logged-in user, potentially compromising sensitive information and functionalities.

Affected Version(s)

Emptoris Services Procurement 10.0.0.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.