Vulnerabilities > Cisco > Prime Service Catalog

DATE CVE VULNERABILITY TITLE RISK
2017-02-03 CVE-2017-3810 Open Redirect vulnerability in Cisco Prime Service Catalog 10.0(R2)Base
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system.
network
low complexity
cisco CWE-601
5.4
2016-07-28 CVE-2016-1462 Cross-site Scripting vulnerability in Cisco Prime Service Catalog 11.0Base
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuz63795.
network
low complexity
cisco CWE-79
6.1