CVE-2021-38868: CSRF
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.
Other sources
IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-38868?
CVE-2021-38868 is a vulnerability in IBM Engineering Requirements Quality Assistant On-Premises that allows an attacker to execute unauthorized actions transmitted from a trusted user.
How severe is CVE-2021-38868?
CVE-2021-38868 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2021-38868?
To fix CVE-2021-38868, update IBM Engineering Requirements Quality Assistant On-Premises to the latest version.
What is the affected software version for CVE-2021-38868?
All versions of IBM Engineering Requirements Quality Assistant On-Premises are affected by CVE-2021-38868.
What is the CWE of CVE-2021-38868?
CVE-2021-38868 is classified under CWE-352, which is Cross-Site Request Forgery (CSRF).