Cisco.Jabber.IM.XMPP.Message.XSS

description-logoDescription

his indicates an attack attempt to exploit a Cross-Site Scripting Vulnerability in Cisco Jabber.
This vulnerability is due to insufficient validation of incoming XMPP messages. A remote attacker can exploit this vulnerability by sending a crafted XMPP message. Successful exploitation could allow the attacker to execute arbitrary code in the context of the application.

affected-products-logoAffected Products

Cisco Jabber 12.1 before 12.1.3
Cisco Jabber 12.5 before 12.5.2
Cisco Jabber 12.6 before 12.6.3
Cisco Jabber 12.7 before 12.7.2
Cisco Jabber 12.8 before 12.8.3
Cisco Jabber 12.9 before 12.9.1

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Refer to the vendor's advisory for updates:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-UyTKCPGg

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-09-22 16.930 Default_action:pass:drop
2020-09-14 16.922