First published: Mon Apr 13 2009(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade_power_action script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Advanced Management Module | =1.36h | |
IBM BladeCenter | =e | |
IBM BladeCenter | =e | |
IBM BladeCenter | =e | |
IBM BladeCenter | =h | |
IBM BladeCenter | =h | |
IBM BladeCenter | =hc10 | |
IBM BladeCenter | =hs12 | |
IBM BladeCenter | =hs12 | |
IBM BladeCenter | =hs12 | |
IBM BladeCenter | =hs20 | |
IBM BladeCenter | =hs21 | |
IBM BladeCenter | =hs21 | |
IBM BladeCenter | =hs21_xm | |
IBM BladeCenter | =hs21_xm | |
IBM BladeCenter | =ht | |
IBM BladeCenter | =ht | |
IBM BladeCenter | =js12 | |
IBM BladeCenter | =js21 | |
IBM BladeCenter | =js21 | |
IBM BladeCenter | =js22 | |
IBM BladeCenter | =ls20 | |
IBM BladeCenter | =ls21 | |
IBM BladeCenter | =ls41 | |
IBM BladeCenter | =qs21 | |
IBM BladeCenter | =qs22 | |
IBM BladeCenter | =s | |
IBM BladeCenter | =s | |
IBM BladeCenter | =t | |
IBM BladeCenter | =t |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.