4.3
CVSSv2

CVE-2014-2193

Published: 20/05/2014 Updated: 20/05/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cisco Unified Web and E-Mail Interaction Manager places session identifiers in GET requests, which allows remote malicious users to inject conversation text by obtaining a valid identifier, aka Bug ID CSCuj43084.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified web and e-mail interaction manager -

Vendor Advisories

A vulnerability in Cisco Unified Web and E-Mail Interaction Manager could allow an unauthenticated, remote attacker to capture, forge, or brute force a session identifier transmitted as a parameter in GET requests The vulnerability is due to improper use of session identifiers in GET requests An attacker could exploit this vulnerability by captu ...