Cross-Site Request Forgery Vulnerability in IBM Engineering Requirements Quality Assistant
CVE-2021-38868

6.5MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 July 2022

Summary

IBM Engineering Requirements Quality Assistant On-Premises is susceptible to cross-site request forgery, a vulnerability that could allow attackers to perform unauthorized actions by exploiting the trust a website places in authenticated users. This could lead to significant security risks, as malicious operations may be executed without the knowledge of users engaged with the platform. It is crucial for organizations using this software to review their configurations and apply recommended security patches to mitigate this risk.

Affected Version(s)

Engineering Requirements Quality Assistant On-Premises All

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.