PT-2015-6454 · Cisco · Cisco Web Security Appliance

Published

2015-06-20

·

Updated

2016-12-28

·

CVE-2015-4198

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Web Security Appliance (WSA) versions 8.5.0-497
Description A cross-site scripting (XSS) issue exists in the web framework, allowing remote attackers to inject arbitrary web script or HTML via an unspecified HTTP header.
Recommendations For version 8.5.0-497, update to a newer version that contains a fix for this issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-4198

Affected Products

Cisco Web Security Appliance