CVE-2009-2047
Summary
| CVE | CVE-2009-2047 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-07-16 15:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Directory traversal vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to read, modify, or delete arbitrary files via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Crs | 3.5 | All | All | All |
| Application | Cisco | Crs | 4.0 | All | All | All |
| Application | Cisco | Crs | 4.1 | All | All | All |
| Application | Cisco | Crs | 4.5 | All | All | All |
| Application | Cisco | Crs | 5.0 | All | All | All |
| Application | Cisco | Crs | 6.0 | All | All | All |
| Application | Cisco | Crs | 7.0 | All | All | All |
| Application | Cisco | Customer Response Applications | 3.5 | All | All | All |
| Application | Cisco | Ip Qm | 3.5 | All | All | All |
| Application | Cisco | Unified Ccx | 3.5 | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(3\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(4\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(5a\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.0\(5\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.5\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 4.5\(2\) | All | All | All |
| Application | Cisco | Unified Ccx | 5.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 6.0\(1\) | All | All | All |
| Application | Cisco | Unified Ccx | 7.0\(1\) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 3.0 | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 5.0\(1\) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 6.0\(1\) | All | All | All |
| Application | Cisco | Unified Ip Contact Center Express | 7.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 3.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 3.1 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 4.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 4.1 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 4.5 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 5.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 6.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 7.0 | All | All | All |
| Application | Cisco | Unified Ip Ivr | 7.0\(1\) | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| osvdb.org/55936 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Cisco Security Advisory: Vulnerabilities in Unified Contact Center Express Administration Pages - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| Cisco Unified Contact Center Express Two Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Cisco Unified Contact Center Express CRS Administration Interface Directory Traversal Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Unified Contact Center Express Express Administration Pages Permit Script Injection and Directory Traversal Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.