Cross-Site Request Forgery Vulnerability in IBM Security Verify Access Appliance
CVE-2024-35138
6.5MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 4 February 2025
What is CVE-2024-35138?
The IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8 are susceptible to a cross-site request forgery attack. This vulnerability allows an attacker to perform unauthorized actions by exploiting the trust of the victim’s browser against the legitimate website. If the victim is authenticated on the site, the attacker can transmit malicious requests, leading to potential unauthorized changes and actions within the application.
Affected Version(s)
Security Verify Access Appliance 10.0.0 <= 10.0.8
Security Verify Access Container 10.0.0 <= 10.0.8