CVE-2018-6497: MFSBGN03810 rev.1 - Universal CMDB, Deserialization Java Objects and CSRF
Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6497?
CVE-2018-6497 refers to a remote Cross-site Request Forgery (CSRF) vulnerability found in UCMBD Server and CMS Server versions.
What is the severity of CVE-2018-6497?
CVE-2018-6497 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2018-6497?
UCMBD Server versions DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND are affected by CVE-2018-6497.
What is the potential impact of CVE-2018-6497?
CVE-2018-6497 could potentially allow for remote unsafe deserialization and cross-site request forgery.
How can I mitigate the vulnerability CVE-2018-6497?
To mitigate CVE-2018-6497, it is recommended to apply the necessary patches and updates provided by Microfocus.