First published: Mon Jan 23 2017(Updated: )
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Webnms Framework | =5.2 | |
Zohocorp Webnms Framework | =5.2-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6603 has a high severity level due to its potential to allow unauthorized user impersonation.
To fix CVE-2016-6603, update your ZOHO WebNMS Framework to the latest available version that addresses this vulnerability.
CVE-2016-6603 affects users of ZOHO WebNMS Framework versions 5.2 and 5.2 SP1.
CVE-2016-6603 is an authentication bypass vulnerability allowing remote attackers to impersonate users.
Yes, CVE-2016-6603 can be exploited remotely by attackers using specific HTTP header manipulations.