CVE-2016-0891: CSRF
Published Apr 20, 2016
·Updated
Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the authentication of administrators.
Affected Software
1 affected component
EMC ViPR SRM<=3.6.4
Event History
Apr 20, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0891?
CVE-2016-0891 is considered a medium severity vulnerability due to the potential for unauthorized access to administrative functions.
2
How do I fix CVE-2016-0891?
The vulnerability can be mitigated by upgrading EMC ViPR SRM to version 3.7 or later.
3
Who is affected by CVE-2016-0891?
CVE-2016-0891 affects all versions of EMC ViPR SRM prior to 3.7, specifically up to version 3.6.4.
4
What type of vulnerability is CVE-2016-0891?
CVE-2016-0891 is a Cross-Site Request Forgery (CSRF) vulnerability affecting administrative interfaces.
5
Can CVE-2016-0891 be exploited remotely?
Yes, CVE-2016-0891 can be exploited remotely by attackers to hijack the authentication of administrators.