Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Case Management application in EMC RSA Adaptive Authentication (On-Premise) before 6.0.2.1.SP3.P4 HF210, 7.0.x and 7.1.x before 7.1.0.0.SP0.P6 HF50, and 7.2.x before 7.2.0.0.SP0.P0 HF20 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emc | Rsa Adaptive Authentication On-Premise | <= 7.2 |
Related Weaknesses (CWE)
References
- http://seclists.org/bugtraq/2016/Sep/33Third Party Advisory
- http://www.securityfocus.com/bid/93025
- http://www.securitytracker.com/id/1036851
- http://seclists.org/bugtraq/2016/Sep/33Third Party Advisory
- http://www.securityfocus.com/bid/93025
- http://www.securitytracker.com/id/1036851
FAQ
What is CVE-2016-0925?
CVE-2016-0925 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross-site scripting (XSS) vulnerability in the Case Management application in EMC RSA Adaptive Authentication (On-Premise) before 6.0.2.1.SP3.P4 HF210, 7.0.x and 7.1.x before 7.1.0.0.SP0.P6 HF50, and...
How severe is CVE-2016-0925?
CVE-2016-0925 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-0925?
Check the references section above for vendor advisories and patch information. Affected products include: Emc Rsa Adaptive Authentication On-Premise.