First published: Sat Mar 12 2016(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM Flash System V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM FlashSystem 9000 Firmware | =7.4 | |
IBM FlashSystem 9000 Firmware | =7.5 | |
IBM FlashSystem 9000 Firmware | =7.6 | |
IBM FlashSystem 9846-AC2 | ||
IBM FlashSystem 9846-AE2 | ||
IBM FlashSystem 9848-AC2 | ||
IBM flashsystem 9848-ae2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7446 is classified as a medium severity vulnerability due to its potential exploitation via cross-site request forgery (CSRF).
To fix CVE-2015-7446, upgrade your IBM Flash System V9000 firmware to versions 7.4.1.4, 7.5.1.3, or 7.6.0.4 or later.
CVE-2015-7446 affects IBM Flash System V9000 firmware versions 7.4 prior to 7.4.1.4, 7.5 prior to 7.5.1.3, and 7.6 prior to 7.6.0.4.
CVE-2015-7446 poses a risk of unauthorized actions being performed by attackers who can exploit CSRF to hijack user authentication.
There are no documented workarounds for CVE-2015-7446, and upgrading is the recommended mitigation.