Cisco Security Advisory
Follow
Cisco UCS Manager Software Stored Cross-Site Scripting Vulnerability
A vulnerability exists in Cisco UCS Manager Software's web-based management interface. This flaw could enable an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability stems from inadequate validation of user-supplied input within the interface. Attackers can exploit this by injecting malicious data into specific interface pages. A successful exploitation allows the attacker to run arbitrary script code within the interface's context. It also permits access to sensitive, browser-based information. To exploit this, the attacker needs Administrator or AAA Administrator role privileges. Cisco has released software updates to fix this vulnerability. Currently, there are no available workarounds. The security impact of this vulnerability is rated as Medium.