7.8
CVSSv2

CVE-2013-1222

Published: 09/05/2013 Updated: 09/05/2013
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Summary

The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software prior to 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote malicious users to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38379.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified customer voice portal 7.0

cisco unified customer voice portal 9.0

cisco unified customer voice portal 8.5\\(1\\)

cisco unified customer voice portal 7.0\\(2\\)

cisco unified customer voice portal 4.0

cisco unified customer voice portal 4.0\\(2\\)

cisco unified customer voice portal 3.0

cisco unified customer voice portal 8.0\\(1\\)

cisco unified customer voice portal 3.6\\(10\\)

cisco unified customer voice portal

cisco unified customer voice portal 4.1

Vendor Advisories

Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities Various components of Cisco Unified CVP are affected; see the "Details" section for more information on the vulnerabilities These vulnerabilities can be exploited independently; however, more than one vulnerability could be exploited on the same device ...