← Back

CVE-2016-0295

nvd nist
Published: Feb 28, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363.

Affected (4)

Products: Ibm: Bigfix Platform
1 product
Bigfix Platform
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 9.5 to 9.5.2
Version 9.0
Version 9.1
Version 9.2

References (4)

Source: psirt@us.ibm.com
MitigationVendor Advisory
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory

Timeline

No history available yet.