Vulnerabilities > Cisco > Prime Infrastructure > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-17 CVE-2017-3869 Unspecified vulnerability in Cisco Prime Infrastructure 3.1(1)
An API Credentials Management vulnerability in the APIs for Cisco Prime Infrastructure could allow an authenticated, remote attacker to access an API that should be restricted to a privileged user.
network
low complexity
cisco
5.4
2016-08-08 CVE-2016-1474 Improper Access Control vulnerability in Cisco Prime Infrastructure 2.2(2)
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuw65846, a different vulnerability than CVE-2015-6434.
network
low complexity
cisco CWE-284
4.3
2016-03-03 CVE-2016-1358 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Prime Infrastructure 2.2/3.0/3.1
Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuw81497.
network
high complexity
cisco CWE-119
6.4
2016-01-08 CVE-2015-6434 Cross-site Scripting vulnerability in Cisco Prime Infrastructure 2.2(2)
Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCux64856.
network
low complexity
cisco CWE-79
6.1