Release date:
Updated on: 2012-05-10
Affected Systems:
Cisco Lan Management Solution 4.0.1
Cisco Lan Management Solution 4.0
Unaffected system:
Cisco Lan Management Solution 4.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53439
Cve id: CVE-2011-4237, CVE-2011-3190
CiscoWorks LAN Management Solution (LMS) is a LAN Management Suite that simplifies configuration, Management, monitoring, and maintenance of CISCO networks.
In versions earlier than CiscoWorks LAN Management Solution (LMS) 4.2, there are two security leaders in implementation, which can be exploited by malicious users to execute HTTP corresponding isolation attacks, leak sensitive information, and bypass certain security restrictions.
1) if the input passed to Autologin. jsp through the URL parameter is not properly filtered, the HTTP header is displayed and can be used to include any HTTP header in the response.
2) there are errors caused by the bundled Apache Tomcat.
<* Source: Nessus
Link: http://secunia.com/advisories/49094/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.cisco.com/warp/public/707/advisory.html