CVE-2016-1474: Medium severity cisco prime infrastructure vulnerability
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuw65846, a different vulnerability than CVE-2015-6434.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1474?
CVE-2016-1474 has been rated with a medium severity level due to its potential for clickjacking attacks.
How do I fix CVE-2016-1474?
To mitigate CVE-2016-1474, users should upgrade Cisco Prime Infrastructure to the latest version available.
What impacts can CVE-2016-1474 cause?
CVE-2016-1474 can allow attackers to perform clickjacking and other unspecified attacks on affected systems.
Which versions of Cisco Prime Infrastructure are affected by CVE-2016-1474?
CVE-2016-1474 specifically impacts Cisco Prime Infrastructure version 2.2(2).
Is there a workaround for CVE-2016-1474 if I cannot update?
There are no specific workarounds for CVE-2016-1474; upgrading to an unaffected version is recommended.