Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified Communications Manager Information Disclosure Vulnerability

cisco-sa-20160817-ucm · Medium · Published · Updated

A vulnerability in the User Data Services (UDS) Application Programming Interface (API) for Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view confidential information that should require authentication. The vulnerability is due to improper authentication controls for certain information returned by the UDS API. An attacker could exploit this vulnerability by accessing the UDS API. An exploit could allow the attacker to view certain information that is confidential and should require authentication to retrieve via the UDS API. Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-ucm

Workarounds

Workarounds are not available.

CVEsCVE-2016-6364
Cisco Bug IDsCSCux67855
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C
Product Names From Source
Cisco Unified Communications Manager

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2016-6364 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2016-6364 Cisco OpenVuln
Cisco Unified Communications Manager CVE-2016-6364 Cisco OpenVuln