Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative users and have other unspecified action, as demonstrated by a request to api/user.
CVSS Vector
AV:N/AC:M/Au:N/C:P/I:P/A:PCarbonblack Carbon Black
APPCarbonblack4.0.34.1.0≤ 4.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2016-9568CRITICAL9.8PL ✓same product
Carbon Black Sensor — nieautoryzowany dostęp przez nieuprzywilejowanego użytkownika
CVE-2016-9570HIGH7.5same product
cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid ...
CVE-2016-9569MEDIUM4.4same product
The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial...
CVE-2018-10407MEDIUM5.5same vendor
An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade thir...