Cisco-SA-20130722-CVE-2013-3439

Cisco Unified Operations Manager HTTP Header Injection Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in Cisco Unified Operations Manager could allow an unauthenticated, remote attacker to cause arbitrary HTML or scripts to be executed in a user's browser. The vulnerability is due to a failure to properly validate application URLs. An attacker could exploit this vulnerability by sending a specially crafted URL to a user in order to introduce arbitrary code into the web interface of Cisco Unified Operations Manager. Cisco has confirmed this vulnerability in a security notice; however, software updates are not available. To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.