admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP...
Vulnerability Description
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-8627
Credits & Attribution
No credits recorded in the NVD database.
References
- http://rhn.redhat.com/errata/RHSA-2017-0250.html
- http://rhn.redhat.com/errata/RHSA-2017-0171.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8627
- https://access.redhat.com/errata/RHSA-2017:3458
- http://rhn.redhat.com/errata/RHSA-2017-0244.html
- http://rhn.redhat.com/errata/RHSA-2017-0172.html
- http://www.securitytracker.com/id/1037660
- http://rhn.redhat.com/errata/RHSA-2017-0246.html
- http://www.securityfocus.com/bid/95698
- https://access.redhat.com/errata/RHSA-2017:3455
- https://access.redhat.com/errata/RHSA-2017:3456
- https://access.redhat.com/errata/RHSA-2017:3454
- http://rhn.redhat.com/errata/RHSA-2017-0170.html
- http://rhn.redhat.com/errata/RHSA-2017-0245.html
- http://rhn.redhat.com/errata/RHSA-2017-0247.html
- http://rhn.redhat.com/errata/RHSA-2017-0173.html
More from [UNKNOWN]
View All →Affected Vendor
[UNKNOWN]
View all reports →