IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 271843.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7107738 | patch vendor advisory |
https://www.ibm.com/support/pages/node/7107740 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/271843 | vdb entry vendor advisory |