PT-2010-3024 · Suse · Suse Lifecycle Management Server+1

Publicado

2010-09-03

·

Atualizado

2017-08-17

·

CVE-2010-1325

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SUSE Lifecycle Management Server (SLMS) version 1.0 on SUSE Linux Enterprise (SLE) 11
Description A cross-site request forgery (CSRF) issue exists due to improper parameter quoting, allowing remote attackers to hijack the authentication of victims.
Recommendations For SUSE Lifecycle Management Server (SLMS) version 1.0 on SUSE Linux Enterprise (SLE) 11, consider implementing proper quoting of parameters to prevent CSRF attacks. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1325

Produtos afetados

Suse Lifecycle Management Server
Suse Linux Enterprise