← Back

CVE-2015-7446

nvd nist
Published: Mar 12, 2016Modified: May 6, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in IBM Flash System V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Affected (3)

1 product
Flashsystem V9000 Firmware
Configuration A
3 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 7.4
Version 7.5
Version 7.6
Running on/withPlatform Versions
Ibm
Flashsystem 9846 Ac2
All versions
Ibm
Flashsystem 9846 Ae2
All versions
Ibm
Flashsystem 9848 Ac2
All versions
Ibm
Flashsystem 9848 Ae2
All versions

References (2)

Source: psirt@us.ibm.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.