CVE-2012-2959: CSRF
Published Jun 11, 2012
·Updated
Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that change passwords.
Affected Software
1 affected component
BMC Identity Management Suite=7.5.00.103
Event History
Jun 11, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2959?
CVE-2012-2959 is classified as a medium severity vulnerability due to its potential for causing unauthorized password changes.
2
How do I fix CVE-2012-2959?
To fix CVE-2012-2959, you should apply the latest patches provided by BMC for Identity Management Suite 7.5.00.103.
3
Who is affected by CVE-2012-2959?
CVE-2012-2959 affects users of BMC Identity Management Suite version 7.5.00.103.
4
What type of vulnerability is CVE-2012-2959?
CVE-2012-2959 is a cross-site request forgery (CSRF) vulnerability.
5
What are the potential impacts of exploiting CVE-2012-2959?
Exploiting CVE-2012-2959 can allow attackers to hijack administrator sessions and change passwords without authorization.