CVE-2016-8583: XSS
Published Oct 28, 2016
·Updated
Multiple GET parameters in the vulnerability scan scheduler of AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS.
Affected Software
2 affected components
AlienVault Open Source Security Information And Event Management<=5.3.1
AlienVault Unified Security Management<=5.3.1
Event History
Oct 28, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-8583?
CVE-2016-8583 is classified as a medium severity vulnerability due to the risk of reflected cross-site scripting (XSS).
2
How do I fix CVE-2016-8583?
To fix CVE-2016-8583, upgrade to AlienVault OSSIM or USM version 5.3.2 or later where the vulnerability has been patched.
3
What systems are affected by CVE-2016-8583?
CVE-2016-8583 affects AlienVault OSSIM and Unified Security Management systems versions prior to 5.3.2.
4
What type of attack does CVE-2016-8583 facilitate?
CVE-2016-8583 can facilitate reflected cross-site scripting (XSS) attacks through vulnerable GET parameters.
5
How can I detect CVE-2016-8583 in my environment?
Detection of CVE-2016-8583 can be performed by scanning for affected versions of AlienVault OSSIM or USM below 5.3.2.