SB2016101209 - Cross-site request forgery in Cisco Finesse
Published: October 12, 2016 Updated: April 5, 2018
Security Bulletin ID
SB2016101209
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site request forgery (CVE-ID: CVE-2016-6442)
The vulnerability allows a remote unauthenticated user to perform cross-site request forgery attack on the target system.The weakness is due to insufficient CSRF protections. By persuading the victim to follow a malicious link or visit an attacker-controlled website, a remote user can send arbitrry requests to the target device via the web browser with the privileges of the valid user.
Successful exploitation of the vulnerability will result in performing of CSRF attack on the vulnerable system.
Remediation
Install update from vendor's website.