CVE-2016-6642: CSRF
Published Sep 18, 2016
·Updated
Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authentication of administrators for requests that upload files.
Affected Software
1 affected component
EMC ViPR SRM<=3.7.1
Event History
Sep 18, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6642?
CVE-2016-6642 is classified as a high severity vulnerability due to its potential to allow authentication hijacking.
2
How do I fix CVE-2016-6642?
To fix CVE-2016-6642, upgrade EMC ViPR SRM to version 3.7.2 or later.
3
What type of attack does CVE-2016-6642 enable?
CVE-2016-6642 enables cross-site request forgery (CSRF) attacks that can hijack administrator authentication.
4
Who is affected by CVE-2016-6642?
Administrators using EMC ViPR SRM versions prior to 3.7.2 are affected by CVE-2016-6642.
5
Can CVE-2016-6642 lead to unauthorized file uploads?
Yes, CVE-2016-6642 can allow remote attackers to upload files by hijacking the authentication of administrators.