6.8

CVE-2009-1290

Exploit

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade_power_action script.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmAdvanced Management Module Version1.36h
   IbmBladecenter Versione Edition1881
   IbmBladecenter Versione Edition7967
   IbmBladecenter Versione Edition8677
   IbmBladecenter Versionh Edition7989
   IbmBladecenter Versionh Edition8852
   IbmBladecenter Versionhc10 Edition7996
   IbmBladecenter Versionhs12 Edition1916
   IbmBladecenter Versionhs12 Edition8014
   IbmBladecenter Versionhs12 Edition8028
   IbmBladecenter Versionhs20 Edition1883
   IbmBladecenter Versionhs21 Edition1885
   IbmBladecenter Versionhs21 Edition8853
   IbmBladecenter Versionhs21_xm Edition1915
   IbmBladecenter Versionhs21_xm Edition7995
   IbmBladecenter Versionht Edition8740
   IbmBladecenter Versionht Edition8750
   IbmBladecenter Versionjs12 Edition7998
   IbmBladecenter Versionjs21 Edition7988
   IbmBladecenter Versionjs21 Edition8844
   IbmBladecenter Versionjs22 Edition7998
   IbmBladecenter Versionls20 Edition8850
   IbmBladecenter Versionls21 Edition7971
   IbmBladecenter Versionls41 Edition7972
   IbmBladecenter Versionqs21 Edition0792
   IbmBladecenter Versionqs22 Edition0793
   IbmBladecenter Versions Edition1948
   IbmBladecenter Versions Edition8886
   IbmBladecenter Versiont Edition8720
   IbmBladecenter Versiont Edition8730
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.613
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.