PT-2017-16103 · Cisco · Cisco Unified Communications Manager

Published

2017-01-26

·

Updated

2017-07-26

·

CVE-2017-3798

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager versions 11.0(1.10000.10) through 11.5(1.10000.6)
Description A cross-site scripting (XSS) filter bypass issue in the web-based management interface could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device.
Recommendations For versions 11.0(1.10000.10) through 11.5(1.10000.6), update to a fixed release such as 11.5(1.12029.1), 11.5(1.12900.11), 12.0(0.98000.369), 12.0(0.98000.370), or 12.0(0.98000.398) to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-3798

Affected Products

Cisco Unified Communications Manager