CVE-2016-8581
Last modified
CVE-2016-8581 is a vulnerability of currently unknown severity. A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.. EPSS estimates a 17.06% chance of exploitation in the next 30 days.
Description
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alienvault | Open Source Security Information And Event Management | <= 5.3.1 |
| Alienvault | Unified Security Management | <= 5.3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8581?
How severe is CVE-2016-8581?
How do I fix CVE-2016-8581?
Are you affected by CVE-2016-8581?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
