VulnerabilityModified
CVE-2010-5283
Cross-site request forgery (CSRF) vulnerability in OpenText ECM (formerly Livelink ECM) 9.7.1 allows remote attackers to hijack the authentication of administrators for requests that change folder and resource permissions.
MEDIUM 6.8EPSS 0.70%
Does this matter?
Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in OpenText ECM (formerly Livelink ECM) 9.7.1 allows remote attackers to hijack the authentication of administrators for requests that change folder and resource permissions.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- opentext/livelink ecm
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0359.htmlExploit
- http://packetstormsecurity.org/1009-exploits/opentext-xsrfxss.txt
- http://secunia.com/advisories/41553Vendor Advisory
- http://www.osvdb.org/68255
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62057
- http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0359.htmlExploit
- http://packetstormsecurity.org/1009-exploits/opentext-xsrfxss.txt
- http://secunia.com/advisories/41553Vendor Advisory
- http://www.osvdb.org/68255
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62057
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.