CVE-2016-6603: Input Validation
Published Jan 23, 2017
·Updated
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.
Affected Software
2 affected components
ZohoCorp Webnms Framework=5.2
ZohoCorp Webnms Framework=5.2-sp1
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6603?
CVE-2016-6603 has a high severity level due to its potential to allow unauthorized user impersonation.
2
How do I fix CVE-2016-6603?
To fix CVE-2016-6603, update your ZOHO WebNMS Framework to the latest available version that addresses this vulnerability.
3
Who is affected by CVE-2016-6603?
CVE-2016-6603 affects users of ZOHO WebNMS Framework versions 5.2 and 5.2 SP1.
4
What type of vulnerability is CVE-2016-6603?
CVE-2016-6603 is an authentication bypass vulnerability allowing remote attackers to impersonate users.
5
Can CVE-2016-6603 be exploited remotely?
Yes, CVE-2016-6603 can be exploited remotely by attackers using specific HTTP header manipulations.