Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified Operations Manager Common Services Device Center Cross-Site Scripting Vulnerability

Cisco-SA-20110518-CVE-2011-0962 · Medium · Published · Updated

Cisco Unified Operations Manager contains a cross-site scripting vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of user input supplied to the Common Services Device Center component used by the affected application.  An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to view a malicious link.  If successful, the attacker could conduct cross-site scripting attacks and access sensitive information. Exploit code is available. Cisco has confirmed this vulnerability; however, software updates are not available. An attacker cannot directly exploit this vulnerability and instead must rely on user participation to accomplish an exploit.  The attacker must convince a user to view a malicious link.  The attacker may provide links to users in e-mail or instant messages or by posting links to public websites.  When followed, the malicious link may trigger the vulnerability and allow the attacker to access sensitive information that may include user credentials.  Attackers could use the information gained from the attack to launch further attacks against a targeted system. This vulnerability was discovered and reported to Cisco Systems by Brett Gervasoni of Sense of Security.

Workarounds

Administrators are advised to apply updates as they become available.

Users are advised not to open e-mail messages from suspicious or unrecognized sources. If users cannot verify that links or attachments included in e-mail messages are safe, they are advised not to open them.

Administrators are advised to monitor affected systems.

CVEsCVE-2011-0962
Cisco Bug IDsNA
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N/E:F/RL:U/RC:C/CDP:N/TD:N/CR:ND/IR:ND/AR:ND
Product Names From Source
Cisco Unified Operations Manager

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Unified Operations Manager known_affected cisco_csaf CVE-2011-0962 1

Related Products

Product CVE Evidence
Cisco Unified Operations Manager CVE-2011-0962 Cisco OpenVuln