CVE-2016-8581
Last modified
CVE-2016-8581 is a vulnerability of currently unknown severity. A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.. EPSS estimates a 17.06% chance of exploitation in the next 30 days.
Description
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alienvault | Open Source Security Information And Event Management | <= 5.3.1 |
| Alienvault | Unified Security Management | <= 5.3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8581?
How severe is CVE-2016-8581?
How do I fix CVE-2016-8581?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-8575The Q.933 parser in tcpdump before 4.9.0 has a buffer overfl…
- CVE-2016-8576The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (a…6
- CVE-2016-8577Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEM…6
- CVE-2016-8578The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c i…6
- CVE-2016-8579docker2aci <= 0.12.3 has an infinite loop when handling loca…
- CVE-2016-8580PHP object injection vulnerabilities exist in multiple widge…
- CVE-2016-8582A vulnerability exists in gauge.php of AlienVault OSSIM and …
- CVE-2016-8583Multiple GET parameters in the vulnerability scan scheduler …
- CVE-2016-8584Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlie…
- CVE-2016-8585admin_sys_time.cgi in Trend Micro Threat Discovery Appliance…
- CVE-2016-8586detected_potential_files.cgi in Trend Micro Threat Discovery…
- CVE-2016-8587dlp_policy_upload.cgi in Trend Micro Threat Discovery Applia…
Are you affected by CVE-2016-8581?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
