5.1
CVSSv2

CVE-2012-2959

Published: 11/06/2012 Updated: 12/06/2012
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote malicious users to hijack the authentication of administrators for requests that change passwords.

Vulnerable Product Search on Vulmon Subscribe to Product

bmc identity management suite 7.5.00.103

Exploits

source: wwwsecurityfocuscom/bid/53924/info Identity Management is prone to a cross-site request-forgery vulnerability because the application fails to properly validate HTTP requests Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user's session and gain unauthorized access to ...