CVE-2009-1290

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade_power_action script.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:advanced_management_module:1.36h:*:*:*:*:*:*:*
OR cpe:2.3:h:ibm:bladecenter:e:*:1881:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:e:*:7967:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:e:*:8677:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:h:*:7989:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:h:*:8852:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hc10:*:7996:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs12:*:1916:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs12:*:8014:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs12:*:8028:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs20:*:1883:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs21:*:1885:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs21:*:8853:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs21_xm:*:1915:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:hs21_xm:*:7995:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:ht:*:8740:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:ht:*:8750:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:js12:*:7998:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:js21:*:7988:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:js21:*:8844:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:js22:*:7998:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:ls20:*:8850:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:ls21:*:7971:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:ls41:*:7972:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:qs21:*:0792:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:qs22:*:0793:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:s:*:1948:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:s:*:8886:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:t:*:8720:*:*:*:*:*
cpe:2.3:h:ibm:bladecenter:t:*:8730:*:*:*:*:*

History

No history.

Information

Published : 2009-04-13 16:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-1290

Mitre link : CVE-2009-1290

CVE.ORG link : CVE-2009-1290


JSON object : View

Products Affected

ibm

  • advanced_management_module
  • bladecenter
CWE
CWE-352

Cross-Site Request Forgery (CSRF)