Vulnerability Name:

CVE-2016-0900 (CCN-112926)

Assigned:2015-12-17
Published:2016-05-04
Updated:2016-12-01
Summary:Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901.
CVSS v3 Severity:6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2016-0900

Source: MISC
Type: UNKNOWN
http://packetstormsecurity.com/files/136994/RSA-Authentication-Manager-XSS-HTTP-Response-Splitting.html

Source: BUGTRAQ
Type: UNKNOWN
20160504 ESA-2016-051: Patch 14 for RSA Authentication Manager 8.1 SP1 to Address Multiple Vulnerabilities

Source: CCN
Type: EMC Security Advisory ESA-2016-051
Patch 14 for RSA Authentication Manager 8.1 SP1 to Address Multiple Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1035755

Source: XF
Type: UNKNOWN
rsa-authentication-cve20160900-xss(112926)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:emc:rsa_authentication_manager:*:sp1:*:*:*:*:*:* (Version <= 8.1)

  • Configuration CCN 1:
  • cpe:/a:emc:rsa_authentication_manager:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:emc:rsa_authentication_manager:8.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    emc rsa authentication manager * sp1
    emc rsa authentication manager 8.0
    emc rsa authentication manager 8.1