Vulnslist

find the latest Cisco vulnerabilities

CVE-2014-3297

Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug IDs CSCui36937, CSCui37004, and CSCui36927.

SeverityMEDIUM
CVSS4.0
CWECWE-264
KEV
Published
Modified

Related Products

Product Advisory
Cisco RV Series Routers Cisco-SA-20140707-CVE-2014-3297
Cisco Nexus Dashboard Cisco-SA-20140707-CVE-2014-3297
Cisco Cloud Portal Cisco-SA-20140707-CVE-2014-3297