CVE-2016-8232: XSS
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8232?
CVE-2016-8232 is rated as a medium severity vulnerability due to its potential impact on the confidentiality of sensitive information.
How do I fix CVE-2016-8232?
To mitigate CVE-2016-8232, update the Advanced Management Module (AMM) to version 66Z or later.
Who is affected by CVE-2016-8232?
CVE-2016-8232 affects users of Lenovo IBM BladeCenter models HS22, HS22V, HS23, HS23E, and HX5 with AMM versions earlier than 66Z.
What kind of attack does CVE-2016-8232 enable?
CVE-2016-8232 allows an unauthenticated attacker to perform cross-site scripting attacks through crafted URLs.
Is CVE-2016-8232 a remote or local attack?
CVE-2016-8232 is considered a remote attack as it can be exploited from outside the network by accessing the AMM's IP address.