CVE-2013-0452
Cross-site request forgery (CSRF) vulnerability in the Software Use Analysis (SUA) application before 1.3.3 in IBM Tivoli Endpoint Manager 8.2 allows remote attackers to hijack the authentication of arbitrary users via a web site that contains crafted…
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in the Software Use Analysis (SUA) application before 1.3.3 in IBM Tivoli Endpoint Manager 8.2 allows remote attackers to hijack the authentication of arbitrary users via a web site that contains crafted Flash Action Message Format (AMF) messages.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- ibm/software use analysis · ibm/tivoli endpoint manager
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV38145
- http://www-01.ibm.com/support/docview.wss?uid=swg21631350Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80968
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV38145
- http://www-01.ibm.com/support/docview.wss?uid=swg21631350Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80968
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.