Cisco Unified Communications Manager CVE-2014-0740 Cross Site Request Forgery Vulnerability
BID:65795
Info
Cisco Unified Communications Manager CVE-2014-0740 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 65795 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0740 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2014 12:00AM |
| Updated: | Feb 25 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Unified Communications Manager (UCM) 0 |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Manager CVE-2014-0740 Cross Site Request Forgery Vulnerability
Cisco Unified Communications Manager is prone to a cross-site request-forgery vulnerability because the application does not properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions in the context of the affected user. Other attacks are also possible.
This issue is being tracked by Cisco bug ID CSCun00701.
Cisco Unified Communications Manager is prone to a cross-site request-forgery vulnerability because the application does not properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions in the context of the affected user. Other attacks are also possible.
This issue is being tracked by Cisco bug ID CSCun00701.
Solution / Fix
Cisco Unified Communications Manager CVE-2014-0740 Cross Site Request Forgery Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Unified Communications Manager CVE-2014-0740 Cross Site Request Forgery Vulnerability
References:
References: