CVE-2016-5372: CSRF
Published Feb 7, 2017
·Updated
Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
Affected Software
1 affected component
NetApp Snap Creator Framework<=4.3.0
Event History
Feb 7, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5372?
CVE-2016-5372 is considered a medium severity cross-site request forgery (CSRF) vulnerability.
2
How do I fix CVE-2016-5372?
To fix CVE-2016-5372, upgrade to NetApp Snap Creator Framework version 4.3.0P1 or later.
3
What types of attacks are possible with CVE-2016-5372?
CVE-2016-5372 allows remote attackers to hijack the authentication of users through CSRF attacks.
4
Who is affected by CVE-2016-5372?
Any users of NetApp Snap Creator Framework versions earlier than 4.3.0P1 are affected by CVE-2016-5372.
5
When was CVE-2016-5372 disclosed?
CVE-2016-5372 was disclosed on June 22, 2016.