Check: 2015-B-0097
Windows 2012 IAVM:
2015-B-0097
(in version v1 r30)
Title
Microsoft Windows UDDI Cross Site Scripting Vulnerability (MS15-087) (Cat II impact)
Discussion
Microsoft has released a security bulletin addressing a vulnerability in the Universal Description, Discovery, and Integration (UDDI) Service. To exploit this vulnerability, an attacker would insert a malicious script into a webpage search parameter. If successfully exploited, the attacker would be able to execute a cross-site scripting (XSS) attack and gain access to sensitive information or caue redirects to a malicious webpage.
Check Content
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-61287
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |