vendor:
Cisco Unified Operations Manager
by:
Sense of Security
3.3
CVSS
LOW
Multiple vulnerabilities including multiple blind SQL injections, multiple XSS and a directory traversal vulnerability
89, 79, 22, 639, 22
CWE
Product Name: Cisco Unified Operations Manager
Affected Version From: CuOM 8.0 and 8.5
Affected Version To: CuOM 8.0 and 8.5
Patch Exists: YES
Related CWE: CVE-2011-0959, CVE-2011-0960, CVE-2011-0961, CVE-2011-0962, CVE-2011-0966
CPE: cisco:cuom
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows
2011
Sense of Security – Security Advisory – SOS-11-006
Multiple vulnerabilities have been identified in Cisco Unified Operations Manager and associated products. These vulnerabilities include multiple blind SQL injections, multiple XSS. and a directory traversal vulnerability. The blind SQL injection vulnerabilities allow an attacker to extract information from the underlying database, the XSS vulnerabilities allow an attacker to inject malicious JavaScript code into the application, and the directory traversal vulnerability allows an attacker to access files outside of the web root.
Mitigation:
Upgrade to CuOM 8.6 as advised by Cisco