8.8
CVSSv3

CVE-2016-0891

Published: 20/04/2016 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM prior to 3.7 allow remote malicious users to hijack the authentication of administrators.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

emc vipr srm

Exploits

<!-- EMC M&R (Watch4net) lacks Cross-Site Request Forgery protection Abstract It was discovered that EMC M&R (Watch4net) does not protect against Cross-Site Request Forgery (CSRF) attacks A successful CSRF attack can compromise end user data and may allow an attacker to perform an account hijack If the targeted end user is the admini ...
EMC ViPR SRM versions prior to 37 suffer from a cross site request forgery vulnerability ...