Cisco Unified Customer Voice Portal Multiple Vulnerabilities
Last Update Date:
9 May 2013 10:05
Release Date:
9 May 2013
3950
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities has been identified in Cisco Unified Customer Voice Portal. A remote user can execute arbitrary applications on the target system, cause denial of service conditions, view and modify files on the target system, and gain administrator access.
- A remote user can send a specially crafted SIP INVITE message to trigger a flaw in the the CallServer component and cause the system to not accept new calls.
- A remote user can exploit a flaw in the Tomcat web application to gain administrator access.
- A remote user can exploit a flaw in the Tomcat web application to execute unauthorized user-supplied web applications.
- A remote user can exploit a parameter validation and file access flaw in the log viewer to view arbitrary system files.
- A remote user can exploit a parameter validation path traversal flaw in Resource Manager component to overwrite system files.
- A remote user can exploit an XML entity expansion flaw to view arbitrary system files.
Impact
- Denial of Service
- Elevation of Privilege
- Remote Code Execution
- Information Disclosure
- Data Manipulation
System / Technologies affected
- prior to 9.0.1 ES 11
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (9.0.1 ES 11)
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp
Vulnerability Identifier
Source
Related Link
Share with