vendor:
BladeCenter Advanced Management Module
by:
SecurityFocus
7.5
CVSS
HIGH
HTML-injection, Cross-site scripting, Information-disclosure, Cross-site request-forgery
79, 79, 200, 352
CWE
Product Name: BladeCenter Advanced Management Module
Affected Version From: 1
Affected Version To: 1.42U
Patch Exists: YES
Related CWE: N/A
CPE: h:ibm:bladecenter_advanced_management_module
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
IBM BladeCenter Advanced Management Module Remote Vulnerabilities
An attacker can exploit these issues to obtain sensitive information, execute arbitrary script code, steal cookie-based authentication credentials, and perform actions as an authenticated user of the application. Other attacks are also possible.
Mitigation:
Upgrade to BladeCenter Advanced Management Module 1.42U or later.