CVE-2016-9149

The Addresses Object parser in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 mishandles single quote characters, which allows remote authenticated users to conduct XPath injection attacks via a crafted string.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:00

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/94401 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/94401 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1037379 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1037379 - Third Party Advisory, VDB Entry
References () https://security.paloaltonetworks.com/CVE-2016-9149 - () https://security.paloaltonetworks.com/CVE-2016-9149 -

Information

Published : 2016-11-19 06:59

Updated : 2024-11-21 03:00


NVD link : CVE-2016-9149

Mitre link : CVE-2016-9149

CVE.ORG link : CVE-2016-9149


JSON object : View

Products Affected

paloaltonetworks

  • pan-os
CWE
CWE-19

Data Processing Errors