Cisco Update
3707Warning Date
Severity Level
Warning Number
Target Sector
5 January, 2020
● High
2020-774
All
Description:
Cisco has released security update to address multiple vulnerabilities in the following product:
- Cisco DCNM
Earlier than Release 11.3(1)
Microsoft Windows, Linux, and virtual appliance platforms
Threats:
Remote attacker could exploit these vulnerabilities by doing the following:
- Unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP)
- Gain access to information that is stored on an affected system.
- Arbitrary Command Injection
- SQL Command Injection
Best practice and Recommendations :
The CERT team encourages users to review Cisco security advisory and apply the necessary update:
https://tools.cisco.com/security/center/publicationListing.x