CVE Database
/

CVE-2016-8627

Back to search

CVE-2016-8627

Published: May 11, 2018

Modified: Aug 6, 2024

PUBLISHED

CVSS v3.0

4.3

MEDIUM

Description

admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.

VendorProductVersions

[UNKNOWN]

admin-cli

affected
admin-cli 3.0.0.Alpha25
affected
admin-cli 2.2.1.CR2

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

Low

References

RHSA-2017:0250
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0171
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3458
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0244
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0172
vendor-advisory
x_refsource_REDHAT
1037660
vdb-entry
x_refsource_SECTRACK
RHSA-2017:0246
vendor-advisory
x_refsource_REDHAT
95698
vdb-entry
x_refsource_BID
RHSA-2017:3455
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3456
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3454
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0170
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0245
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0247
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0173
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now