First published: Fri Mar 17 2017(Updated: )
A vulnerability in the web framework code of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc79842 CSCvc79846 CSCvc79855 CSCvc79873 CSCvc79882 CSCvc79891. Known Affected Releases: 11.1.2.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Service Catalog | =11.1.2 | |
Cisco Prime Service Catalog | =11.1_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3866 has a high severity rating due to its potential for enabling cross-site scripting attacks.
To fix CVE-2017-3866, update your Cisco Prime Service Catalog to the latest version that addresses this vulnerability.
CVE-2017-3866 affects Cisco Prime Service Catalog versions 11.1.2 and 11.1_base.
Yes, CVE-2017-3866 can be exploited remotely by an unauthenticated attacker through the web interface.
CVE-2017-3866 can facilitate a cross-site scripting (XSS) attack against users of the affected web interface.