CVE-2011-0962
Summary
| CVE | CVE-2011-0962 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-05-20 22:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Unified Operations Manager | 1.1 | All | All | All |
| Application | Cisco | Unified Operations Manager | 2.0 | All | All | All |
| Application | Cisco | Unified Operations Manager | 2.0.1 | All | All | All |
| Application | Cisco | Unified Operations Manager | 2.0.2 | All | All | All |
| Application | Cisco | Unified Operations Manager | 2.0.3 | All | All | All |
| Application | Cisco | Unified Operations Manager | 2.1 | All | All | All |
| Application | Cisco | Unified Operations Manager | 2.2 | All | All | All |
| Application | Cisco | Unified Operations Manager | 2.3 | All | All | All |
| Application | Cisco | Unified Operations Manager | 8.0 | All | All | All |
| Application | Cisco | Unified Operations Manager | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Alert Details - Security Center - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | |
| Page Not Found | Sense of Security | af854a3a-2127-422b-91ae-364da2661108 | www.senseofsecurity.com.au | Exploit, URL Repurposed |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Unified Operations Manager Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| archives.neohapsis.com/archives/fulldisclosure/2011-05/0371.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.