First published: Thu Feb 16 2017(Updated: )
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 Identity Server | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-4311 is classified as medium due to its ability to allow remote attackers to hijack authentication of privileged users.
To fix CVE-2016-4311, it is recommended to upgrade to a patched version of WSO2 Identity Server that addresses the CSRF vulnerability.
CVE-2016-4311 affects WSO2 Identity Server version 5.1.0.
CVE-2016-4311 can facilitate cross-site request forgery (CSRF) attacks, allowing unauthorized actions on behalf of a privileged user.
CVE-2016-4311 is a server-side vulnerability that affects the authentication mechanism in WSO2 Identity Server.