CVE-2017-3874: XSS
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. More Information: CSCvb70033. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.507) 11.0(1.23900.5) 11.0(1.23900.3) 10.5(2.15900.2).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Unified Communications Manager (CallManager)to a version that resolves this vulnerability.Fixed in 12.0(0.98000.507) - Upgrade
Upgrade
Cisco Unified Communications Manager (CallManager)to a version that resolves this vulnerability.Fixed in 11.0(1.23900.5) - Upgrade
Upgrade
Cisco Unified Communications Manager (CallManager)to a version that resolves this vulnerability.Fixed in 11.0(1.23900.3) - Upgrade
Upgrade
Cisco Unified Communications Manager (CallManager)to a version that resolves this vulnerability.Fixed in 10.5(2.15900.2) - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CSCvb70033
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3874?
CVE-2017-3874 is classified as a moderate severity vulnerability.
How do I fix CVE-2017-3874?
To fix CVE-2017-3874, upgrade to a fixed release of Cisco Unified Communications Manager, such as 12.0(0.98000.507) or later.
What type of attack is possible with CVE-2017-3874?
CVE-2017-3874 allows an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack.
Which versions of Cisco Unified Communications Manager are affected by CVE-2017-3874?
CVE-2017-3874 affects Cisco Unified Communications Manager version 11.5(1.11007.2).
Is CVE-2017-3874 exploitable without authentication?
No, CVE-2017-3874 requires authentication for the attack to be executed.