CVE-2015-4198: XSS
Published Jun 20, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified HTTP header, aka Bug ID CSCuu24409.
Affected Software
1 affected component
Cisco Web Security Appliance=8.5.0-497
Event History
Jun 20, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4198?
CVE-2015-4198 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-4198?
To remediate CVE-2015-4198, upgrade your Cisco Web Security Appliance to the latest software version provided by Cisco.
3
What causes CVE-2015-4198?
CVE-2015-4198 is caused by improper validation of HTTP headers, which allows for cross-site scripting (XSS) attacks.
4
What are the potential impacts of exploiting CVE-2015-4198?
Exploiting CVE-2015-4198 can enable attackers to inject arbitrary web scripts or HTML into affected web applications.
5
Which versions of Cisco Web Security Appliance are affected by CVE-2015-4198?
CVE-2015-4198 affects Cisco Web Security Appliance version 8.5.0-497.