Description
|
|
Multiple vulnerabilities have been identified in IBM BladeCenter Advanced Management Module, which could be exploited by attackers to disclose sensitive information or manipulate certain data.
The first issue is caused by an input validation error in the administrative interface when processing user-supplied logins, which could allow malicious users to conduct cross site scripting attacks.
The second vulnerability is caused by an input validation error in the "private/file_management.ssi" script when processing the "PATH" parameter, which could allow cross site scripting attacks.
The third issue is caused by an error in the administrative interface, which could allow malicious users to view security permissions of other users.
The fourth vulnerability is caused by an error in the administrative interface when processing certain HTTP requests, which could be exploited to conduct cross site request forgery attacks.
The fifth issue is caused by an unspecified error which could allow port forwarding using SSH.
|