CVE-2016-6647: XSS
Published Sep 30, 2016
·Updated
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
EMC ViPR SRM<=4.0
Event History
Sep 30, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6647?
The CVE-2016-6647 vulnerability has a medium severity rating due to its potential impact on user sessions and data integrity.
2
How do I fix CVE-2016-6647?
To mitigate CVE-2016-6647, upgrade EMC ViPR SRM to version 4.0.1 or later.
3
Who is affected by CVE-2016-6647?
Remote authenticated users of EMC ViPR SRM versions prior to 4.0.1 are affected by CVE-2016-6647.
4
What types of attacks are possible with CVE-2016-6647?
CVE-2016-6647 allows for cross-site scripting (XSS) attacks, enabling attackers to inject arbitrary web scripts or HTML.
5
What software versions are vulnerable to CVE-2016-6647?
EMC ViPR SRM versions prior to 4.0.1 are vulnerable to CVE-2016-6647.