CVE-2017-3798: XSS
A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device. More Information: CSCvb97237. Known Affected Releases: 11.0(1.10000.10) 11.5(1.10000.6). Known Fixed Releases: 11.5(1.12029.1) 11.5(1.12900.11) 12.0(0.98000.369) 12.0(0.98000.370) 12.0(0.98000.398) 12.0(0.98000.457).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 11.5(1.12029.1)Patch CSCvb97237 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 11.5(1.12900.11)Patch CSCvb97237 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.369)Patch CSCvb97237 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.370)Patch CSCvb97237 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.398)Patch CSCvb97237 - Upgrade
Upgrade
Cisco Unified Communications Managerto a version that resolves this vulnerability.Fixed in 12.0(0.98000.457)Patch CSCvb97237
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3798?
CVE-2017-3798 has been classified as a medium severity vulnerability.
How do I fix CVE-2017-3798?
To fix CVE-2017-3798, it is recommended to apply the latest patches and updates provided by Cisco for Unified Communications Manager.
What type of attack does CVE-2017-3798 facilitate?
CVE-2017-3798 facilitates cross-site scripting (XSS) attacks against users of affected devices.
Who is vulnerable to CVE-2017-3798?
Unauthenticated, remote attackers can exploit CVE-2017-3798 against users of affected Cisco Unified Communications Manager devices.
Which Cisco Unified Communications Manager versions are affected by CVE-2017-3798?
Cisco Unified Communications Manager version 11.5(1.12000.1) is among the affected releases for CVE-2017-3798.