Release date:
Updated on: 2013-09-23
Affected Systems:
Cisco Prime Data Center Network Manager 6.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 62485
CVE (CAN) ID: CVE-2013-5490
Cisco Prime Data Center Network Manager helps you effectively execute and manage virtualized Data centers.
Cisco Prime Data Center Network Manager 6.1 has errors when processing XML Data. by sending specially crafted XML Data that includes external entity references, some local file content may be leaked.
<* Source: TippingPoint's Zero Day Initiative (ZDI)
Link: http://www.securelist.com/en/advisories/54843
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.cisco.com/go/psirt
Http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130918-dcnm