Lucene search

K
cvelistIbmCVELIST:CVE-2021-20403
HistoryFeb 11, 2021 - 4:30 p.m.

CVE-2021-20403

2021-02-1116:30:30
ibm
www.cve.org
3
ibm
security
verify
information
queue
cross-site request forgery
unauthorized actions
attacker

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

30.0%

IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

CNA Affected

[
  {
    "product": "Security Verify Information Queue",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "1.0.6"
      },
      {
        "status": "affected",
        "version": "1.0.7"
      }
    ]
  }
]

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

30.0%

Related for CVELIST:CVE-2021-20403