5
CVSSv2

CVE-2014-0725

Published: 13/02/2014 Updated: 13/02/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote malicious users to obtain sensitive information via unspecified access to a "file storage location," aka Bug ID CSCum05337.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager

Vendor Advisories

A vulnerability in the availability of Cisco Unified Communications Manager (UCM) web archive (WAR) files could allow an unauthenticated, remote attacker to access the files The vulnerability is due to missing authentication requirements on locations that store WAR files An attacker could exploit this vulnerability by connecting to the file sto ...