CVE-2018-2001: CSRF
IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154891.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2001?
The severity of CVE-2018-2001 is high.
What is the vulnerability description of CVE-2018-2001?
CVE-2018-2001 is a cross-site request forgery vulnerability in IBM Cram Social Program Management that allows unauthorized actions.
Which software versions are affected by CVE-2018-2001?
IBM Curam Social Program Management versions 6.1.1, 6.2.0, 7.0.4, and 7.0.5 are affected by CVE-2018-2001.
How can an attacker exploit CVE-2018-2001?
An attacker can exploit CVE-2018-2001 by executing malicious actions through a trusted user on the vulnerable website.
Are there any references for CVE-2018-2001?
Yes, you can find references for CVE-2018-2001 at the following links: (1) [IBM X-Force ID: 154891](https://exchange.xforce.ibmcloud.com/vulnerabilities/154891), (2) [IBM Support Document](https://www.ibm.com/support/docview.wss?uid=ibm10883184).