5
CVSSv2

CVE-2015-0763

Published: 04/06/2015 Updated: 04/01/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote malicious users to obtain sensitive session information via a crafted URL, aka Bug ID CSCuu60338.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified meetingplace 8.6\\(1.2\\)

Vendor Advisories

A vulnerability in the Cisco Unified MeetingPlace application could allow an unauthenticated, remote attacker to obtain sensitive information The Cisco Unified MeetingPlace application does not always properly validate the session ID in the HTTP URL This could allow an attacker to obtain sensitive information about a session to use to compromise ...