CVE-2016-0902: CRLF Injection
Published May 7, 2016
·Updated
CRLF injection vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected Software
1 affected component
EMC RSA Authentication Manager<=8.1
Event History
May 7, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0902?
CVE-2016-0902 has a low severity rating that allows for HTTP response splitting attacks.
2
How do I fix CVE-2016-0902?
To mitigate CVE-2016-0902, upgrade EMC RSA Authentication Manager to version 8.1 SP1 P14 or later.
3
What type of attacks can be conducted through CVE-2016-0902?
CVE-2016-0902 allows attackers to perform HTTP response splitting attacks by injecting arbitrary HTTP headers.
4
Which versions of RSA Authentication Manager are affected by CVE-2016-0902?
CVE-2016-0902 affects all versions of EMC RSA Authentication Manager prior to 8.1 SP1 P14.
5
Is there any publicly available information regarding CVE-2016-0902?
Yes, CVE-2016-0902 has been discussed in various security forums and vulnerability databases.