PT-2017-7466 · Alcatel Lucent · Alcatel-Lucent Motive Home Device Manager

Uceka

+1

·

Published

2017-03-23

·

Updated

2017-03-28

·

CVE-2015-8687

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Alcatel-Lucent Motive Home Device Manager (HDM) versions prior to 4.2
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the Management Console of Alcatel-Lucent Motive Home Device Manager (HDM). These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via various parameters, including the deviceTypeID parameter to "DeviceType/getDeviceType.do", the policyActionClass or policyActionName parameter to "PolicyAction/findPolicyActions.do", the deviceID parameter to "SingleDeviceMgmt/getDevice.do" or "device/editDevice.do", the operation parameter to "ajax.do" or "xmlHttp.do", and the policyAction, policyClass, or policyName parameter to "policy/findPolicies.do".
Recommendations For versions prior to 4.2, update to version 4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Management Console and limiting the use of the affected parameters until the update is applied. Avoid using the vulnerable parameters in the affected API endpoints until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8687

Affected Products

Alcatel-Lucent Motive Home Device Manager