CVE-2014-2193

Cisco Unified Web and E-Mail Interaction Manager places session identifiers in GET requests, which allows remote attackers to inject conversation text by obtaining a valid identifier, aka Bug ID CSCuj43084.

SeverityMEDIUM
CVSS4.3
EPSS-
CWECWE-20
KEV
Published
Modified

Public Affected Products

Product Advisory Evidence
Cisco Unified Web and E-Mail Interaction Manager Cisco-SA-20140520-CVE-2014-2193 Cisco CSAF ยท structured affected