CVE-2016-8232
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information.
Published:Mar 1, 2017
Last Modified:Apr 20, 2025
EPS:Mar 1, 2017
EPSS Score:0.00242
CVSS Score:6.1
Affected Products
Vendor
Product
Action
Vendor
Ibm
Product
Advanced Management Module
Ibm
Advanced Management Module
Vendor
Ibm
Product
Advanced Management Module Firmware
Ibm
Advanced Management Module Firmware
Vendor
Ibm
Product
Bladecenter
Ibm
Bladecenter
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
