First published: Tue Dec 19 2017(Updated: )
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz for Service Management | =1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1746 is high with a severity value of 8.8.
CVE-2017-1746 is vulnerable to cross-site request forgery (CSRF).
An attacker can exploit CVE-2017-1746 by executing malicious and unauthorized actions transmitted from a trusted user on the affected website.
The affected software of CVE-2017-1746 is IBM Jazz for Service Management (IBM Tivoli Components 1.1.3).
The Common Weakness Enumeration (CWE) of CVE-2017-1746 is CWE-352.