First published: Tue Apr 02 2019(Updated: )
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144348.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Privileged Identity Manager Virtual Appliance | =2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1622 is classified as a medium severity vulnerability due to its potential to allow unauthorized actions.
To fix CVE-2018-1622, it is recommended to apply patches or updates provided by IBM for the affected versions of IBM Security Privileged Identity Manager.
CVE-2018-1622 can lead to unauthorized actions being executed by an attacker through cross-site request forgery.
CVE-2018-1622 affects IBM Security Privileged Identity Manager version 2.1.1 and earlier.
Yes, CVE-2018-1622 requires user interaction for an attacker to exploit the cross-site request forgery vulnerability.