CVE-2020-3192
published 2020-03-04CVE-2020-3192: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.80%
52.5th percentile
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_prime_collaboration_provisioning | >= unspecified < n/a | n/a |
| cisco | prime_collaboration_provisioning | < 12.6 | 12.6 |
| cisco | prime_collaboration_provisioning | — | — |
| cisco | prime_collaboration_provisioning | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Collaboration Provisioning Cross-Site Scripting Vulnerability
vendor_cisco·2020-03-04·CVSS 6.1
CVE-2020-3192 [MEDIUM] CWE-79 Cisco Prime Collaboration Provisioning Cross-Site Scripting Vulnerability
Cisco Prime Collaboration Provisioning Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.
The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
There are no workarounds that address this vulnerability.
This advisory is available at the follow
Cisco
Cisco Prime Collaboration Provisioning Cross-Site Scripting Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3192 Cisco Prime Collaboration Provisioning Cross-Site Scripting Vulnerability
CVE-2020-3192: Cisco Prime Collaboration Provisioning Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. There are no
CVSS: 3.0
CWE: CWE-79, CWE-79
Bug IDs: CSCvs29654
GHSA
GHSA-3hq2-84r5-gccw: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to con
ghsa_unreviewed·2022-05-24
CVE-2020-3192 [MEDIUM] GHSA-3hq2-84r5-gccw: A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to con
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9827 hawtio: server side request forgery via initial /proxy/ substring of a URI
bugzilla·2019-07-10·CVSS 9.8
CVE-2019-9827 [CRITICAL] CVE-2019-9827 hawtio: server side request forgery via initial /proxy/ substring of a URI
CVE-2019-9827 hawtio: server side request forgery via initial /proxy/ substring of a URI
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
Reference:
https://www.ciphertechs.com/hawtio-advisory/
Discussion:
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss A-MQ 6
* Red Hat JBoss Fuse 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
This issue has been addressed in the following products:
Red Hat Fuse 7.7.0
Via RHSA-2020:3192 https://access.redhat.com/errata/RHSA-2020:3192
---
This bug is now closed. Further updates for individual products will
Bugzilla
CVE-2019-3797 spring-data-jpa: Additional information exposure with Spring Data JPA derived queries
bugzilla·2019-04-08·CVSS 3.5
CVE-2019-3797 [LOW] CVE-2019-3797 spring-data-jpa: Additional information exposure with Spring Data JPA derived queries
CVE-2019-3797 spring-data-jpa: Additional information exposure with Spring Data JPA derived queries
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘endingWith’ or ‘containing’ could return more results than anticipated when a maliciously crafted query parameter value is supplied. Also, LIKE expressions in manually defined queries could return unexpected results if the parameter values bound did not have escaped reserved characters properly.
References:
https://pivotal.io/security/cve-2019-3797
Discussion:
This issue has been addressed in the following products:
Red Hat Fuse 7.7.0
Via RHSA-2020:3192 https://access.redhat.com/errata/RHSA-2020:3192
---
This bug is now closed. Further
2020-03-04
Published