Cisco 9.9/10-severity bug: Patch these dangerous Jabber flaw

Cisco 9.9/10-severity bug: Patch these dangerous Jabber flaws for Windows, macOS


SEE:
(TechRepublic Premium)
Cisco says the bugs allow an attacker to "execute arbitrary programs on the underlying operating system with elevated privileges or gain access to sensitive information". Customers have no other option but to install the latest updates to prevent attacks. 
Norwegian security outfit Watchcom found earlier this year that Jabber was vulnerable to cross-site scripting (XSS) through XHTML-IM messages. Jabber did not properly sanitize incoming HTML messages and instead passed them through a faulty XSS filter.
Cisco notes that the new message-handling vulnerabilities can be exploited if an attacker can send Extensible Messaging and Presence Protocol (XMPP) messages to end-user systems running Cisco Jabber. 

Related Keywords

Norway , Norwegian , Fredrik Bugge Lyche , , Chromium Embedded Framework , Techrepublic Premium , Extensible Messaging , Presence Protocol , Fredrik Bugge , Cisco Jabber , நோர்வே , குரோமியம் பதிக்கப்பட்ட கட்டமைப்பு , ப்ரெஸெந்ஸ் ப்ரோடொகால் , சிஸ்கோ ஜாபர் ,

© 2025 Vimarsana