Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106453
Category:CISCO
Title:Cisco Unified Communications Manager IM and Presence Service Information Disclosure Vulnerability
Summary:A vulnerability in the web management interface of the Cisco Unified;Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view;information on web pages that should be restricted.
Description:Summary:
A vulnerability in the web management interface of the Cisco Unified
Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view
information on web pages that should be restricted.

Vulnerability Insight:
The vulnerability is due to a lack of proper input validation performed on
the HTTP packet header. An attacker could exploit this vulnerability by sending a crafted packet to the targeted
device.

Vulnerability Impact:
An exploit could allow the attacker to view web pages that should have been
restricted.

Affected Software/OS:
Versions 10.5(1), 10.5(2), 11.0(1) and 11.5(1)

Solution:
See the vendors advisory for solutions.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-6464
BugTraq ID: 94802
http://www.securityfocus.com/bid/94802
http://www.securitytracker.com/id/1037412
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.