6.8
CVSSv2

CVE-2013-6443

Published: 23/01/2014 Updated: 23/01/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

CloudForms 3.0 Management Engine prior to 5.2.1.6 allows remote malicious users to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cloudforms 3.0

redhat cloudforms 3.0 management engine 5.2

redhat cloudforms 3.0 management engine

Vendor Advisories

Synopsis Moderate: cfme security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated cfme packages that fix one security issue, several bugs, and addvarious enhancements are now available for Red Hat CloudForms 30The Red Hat Security Response Team has rated this update ...