5
CVSSv2

CVE-2016-6364

Published: 23/08/2016 Updated: 12/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote malicious users to bypass intended access restrictions and obtain sensitive information via unspecified API calls, aka Bug ID CSCux67855.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager 11.5.0

Vendor Advisories

A vulnerability in the User Data Services (UDS) Application Programming Interface (API) for Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view confidential information that should require authentication The vulnerability is due to improper authentication controls for certain information returned by the UD ...