Cisco Prime Service Catalog CVE-2015-0581 XML External Entity Injection Vulnerability
BID:72350
Info
Cisco Prime Service Catalog CVE-2015-0581 XML External Entity Injection Vulnerability
| Bugtraq ID: | 72350 |
| Class: | Design Error |
| CVE: |
CVE-2015-0581 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2015 12:00AM |
| Updated: | Jan 29 2015 12:00AM |
| Credit: | Alexios Dimitriadis and Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Prime Service Catalog CVE-2015-0581 XML External Entity Injection Vulnerability
Cisco Prime Service Catalog is prone to an XML External Entity injection vulnerability because the application fails to properly handle external XML data.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Cisco Prime Service Catalog is prone to an XML External Entity injection vulnerability because the application fails to properly handle external XML data.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Exploit / POC
Cisco Prime Service Catalog CVE-2015-0581 XML External Entity Injection Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Cisco Prime Service Catalog CVE-2015-0581 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Prime Service Catalog CVE-2015-0581 XML External Entity Injection Vulnerability
References:
References:
- Cisco Homepage (Cisco )