Vulnerability Description
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Advanced Management Module Firmware | - |
| Ibm | Advanced Management Module | - |
| Ibm | Bladecenter | hs22 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95839Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/121443Third Party Advisory
- https://support.lenovo.com/us/en/product_security/LEN-5700Vendor Advisory
- http://www.securityfocus.com/bid/95839Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/121443Third Party Advisory
- https://support.lenovo.com/us/en/product_security/LEN-5700Vendor Advisory
FAQ
What is CVE-2016-8232?
CVE-2016-8232 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an...
How severe is CVE-2016-8232?
CVE-2016-8232 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8232?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Advanced Management Module Firmware, Ibm Advanced Management Module, Ibm Bladecenter.