CVE-2018-1622: CSRF
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144348.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1622?
CVE-2018-1622 is classified as a medium severity vulnerability due to its potential to allow unauthorized actions.
How do I fix CVE-2018-1622?
To fix CVE-2018-1622, it is recommended to apply patches or updates provided by IBM for the affected versions of IBM Security Privileged Identity Manager.
What impact does CVE-2018-1622 have on affected software?
CVE-2018-1622 can lead to unauthorized actions being executed by an attacker through cross-site request forgery.
Which versions of IBM Security Privileged Identity Manager are affected by CVE-2018-1622?
CVE-2018-1622 affects IBM Security Privileged Identity Manager version 2.1.1 and earlier.
Is user action needed to exploit CVE-2018-1622?
Yes, CVE-2018-1622 requires user interaction for an attacker to exploit the cross-site request forgery vulnerability.