6.8
CVSSv2

CVE-2009-1290

Published: 13/04/2009 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote malicious users to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade_power_action script.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm advanced_management_module 1.36h

Exploits

source: wwwsecurityfocuscom/bid/34447/info IBM BladeCenter Advanced Management Module is prone to the following remote vulnerabilities: - An HTML-injection vulnerability - A cross-site scripting vulnerability - An information-disclosure vulnerability - Multiple cross-site request-forgery vulnerabilities An attacker can exploit the ...