Cross-Site Request Forgery Vulnerability in IBM Spectrum Protect Operations Center
CVE-2022-22346

4.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
14 March 2022

Summary

IBM Spectrum Protect Operations Center versions 8.1.0.000 through 8.1.13.xxx are susceptible to cross-site request forgery (CSRF). This vulnerability allows attackers to carry out unauthorized actions on behalf of unsuspecting users who are authenticated on the system. An exploit could enable a malicious actor to run arbitrary commands or access sensitive data, putting user environments at significant risk. Users are recommended to apply security patches and enhance their operational security protocols to mitigate potential threats.

Affected Version(s)

Spectrum Protect Operations Center 8.1.0.000

Spectrum Protect Operations Center 8.1.13

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.