Multiple Vulnerabilities in Cisco UCS Central Software

Related Vulnerabilities: CVE-2017-12348   CVE-2017-12349  

Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface. For more information about these vulnerabilities, see the “Details” section of this security advisory. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-ucs-central