vendor:
ViPR SRM
by:
ESA-2016-039
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: ViPR SRM
Affected Version From: Versions of EMC ViPR SRM prior to version 3.7
Affected Version To: Version 3.7
Patch Exists: YES
Related CWE: CVE-2016-0891
CPE: emc:vipr_srm
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
EMC M&R (Watch4net) lacks Cross-Site Request Forgery protection
It was discovered that EMC M&R (Watch4net) does not protect against Cross-Site Request Forgery (CSRF) attacks. A successful CSRF attack can compromise end user data and may allow an attacker to perform an account hijack. If the targeted end user is the administrator account, this results in a full compromise of Watch4net.
Mitigation:
EMC released 34247_ViPR-SRM to fix these vulnerabilities.