CNNVD-202602-558 Information

CNNVD ID

CNNVD-202602-558

CVE-2024-40685

  • CNNVD Published: 2026-02-04

Description (Chinese)

IBM Operations Analytics - Log Analysis是美国国际商业机器(IBM)公司的一款日志分析软件。 IBM Operations Analytics – Log Analysis 1.3.5.0版本至1.3.8.3版本存在跨站请求伪造漏洞,该漏洞源于容易受到跨站请求伪造攻击,可能允许攻击者诱骗受信任用户执行未授权操作。

Description (English)

IBM Operations Analytics - Log Analysis software for IBM. The IBM Operations – Log Analysis Versions 1.3.5.0 to 1.3.8.3 have a false gap in cross-site requests, which stems from the vulnerability of cross-site requests to false attacks, which may allow the attackers to lure trusted users into unauthorized operations.

Hazard Level

High

Vulnerability Type

跨站请求伪造

Affected Vendor

国际商业机器

Published

2026-02-04

Last Modified

2026-02-24

References

https://www.ibm.com/support/pages/node/7256429

Patch

https://www.ibm.com/support/pages/node/7256429

Share on: