CVE Vulnerabilities

CVE-2014-0657

Published: Jan 08, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly handle role restrictions, which allows remote authenticated users to bypass role-based access control via multiple visits to a forbidden portal URL, aka Bug ID CSCuj83540.

Affected Software

Name Vendor Start Version End Version
Unified_communications_manager Cisco * 9.1(1) (including)
Unified_communications_manager Cisco 3.3(5) (including) 3.3(5) (including)
Unified_communications_manager Cisco 3.3(5)sr1 (including) 3.3(5)sr1 (including)
Unified_communications_manager Cisco 3.3(5)sr2a (including) 3.3(5)sr2a (including)
Unified_communications_manager Cisco 4.1(3) (including) 4.1(3) (including)
Unified_communications_manager Cisco 4.1(3)sr1 (including) 4.1(3)sr1 (including)
Unified_communications_manager Cisco 4.1(3)sr2 (including) 4.1(3)sr2 (including)
Unified_communications_manager Cisco 4.1(3)sr3 (including) 4.1(3)sr3 (including)
Unified_communications_manager Cisco 4.1(3)sr4 (including) 4.1(3)sr4 (including)
Unified_communications_manager Cisco 4.2 (including) 4.2 (including)
Unified_communications_manager Cisco 4.2.1 (including) 4.2.1 (including)
Unified_communications_manager Cisco 4.2.2 (including) 4.2.2 (including)
Unified_communications_manager Cisco 4.2.3 (including) 4.2.3 (including)
Unified_communications_manager Cisco 4.2.3sr1 (including) 4.2.3sr1 (including)
Unified_communications_manager Cisco 4.2.3sr2 (including) 4.2.3sr2 (including)
Unified_communications_manager Cisco 4.2.3sr2b (including) 4.2.3sr2b (including)
Unified_communications_manager Cisco 4.3 (including) 4.3 (including)
Unified_communications_manager Cisco 4.3(1) (including) 4.3(1) (including)
Unified_communications_manager Cisco 5.0 (including) 5.0 (including)
Unified_communications_manager Cisco 5.1 (including) 5.1 (including)
Unified_communications_manager Cisco 5.1(1) (including) 5.1(1) (including)
Unified_communications_manager Cisco 5.1(1b) (including) 5.1(1b) (including)
Unified_communications_manager Cisco 5.1(1c) (including) 5.1(1c) (including)
Unified_communications_manager Cisco 5.1(2) (including) 5.1(2) (including)
Unified_communications_manager Cisco 5.1(2a) (including) 5.1(2a) (including)
Unified_communications_manager Cisco 5.1(2b) (including) 5.1(2b) (including)
Unified_communications_manager Cisco 5.1(3) (including) 5.1(3) (including)
Unified_communications_manager Cisco 5.1(3a) (including) 5.1(3a) (including)
Unified_communications_manager Cisco 5.1(3c) (including) 5.1(3c) (including)
Unified_communications_manager Cisco 5.1(3d) (including) 5.1(3d) (including)
Unified_communications_manager Cisco 5.1(3e) (including) 5.1(3e) (including)
Unified_communications_manager Cisco 5.1.2 (including) 5.1.2 (including)
Unified_communications_manager Cisco 6.0 (including) 6.0 (including)
Unified_communications_manager Cisco 6.0(1) (including) 6.0(1) (including)
Unified_communications_manager Cisco 6.0(1a) (including) 6.0(1a) (including)
Unified_communications_manager Cisco 6.0(1b) (including) 6.0(1b) (including)
Unified_communications_manager Cisco 6.1(1) (including) 6.1(1) (including)
Unified_communications_manager Cisco 6.1(1a) (including) 6.1(1a) (including)
Unified_communications_manager Cisco 6.1(1b) (including) 6.1(1b) (including)
Unified_communications_manager Cisco 6.1(2) (including) 6.1(2) (including)
Unified_communications_manager Cisco 6.1(2)su1 (including) 6.1(2)su1 (including)
Unified_communications_manager Cisco 6.1(2)su1a (including) 6.1(2)su1a (including)
Unified_communications_manager Cisco 6.1(3) (including) 6.1(3) (including)
Unified_communications_manager Cisco 6.1(3a) (including) 6.1(3a) (including)
Unified_communications_manager Cisco 6.1(3b) (including) 6.1(3b) (including)
Unified_communications_manager Cisco 6.1(3b)su1 (including) 6.1(3b)su1 (including)
Unified_communications_manager Cisco 6.1(4) (including) 6.1(4) (including)
Unified_communications_manager Cisco 6.1(4)su1 (including) 6.1(4)su1 (including)
Unified_communications_manager Cisco 6.1(4a) (including) 6.1(4a) (including)
Unified_communications_manager Cisco 6.1(4a)su2 (including) 6.1(4a)su2 (including)
Unified_communications_manager Cisco 6.1(5) (including) 6.1(5) (including)
Unified_communications_manager Cisco 6.1(5)su1 (including) 6.1(5)su1 (including)
Unified_communications_manager Cisco 6.1(5)su2 (including) 6.1(5)su2 (including)
Unified_communications_manager Cisco 6.1(5)su3 (including) 6.1(5)su3 (including)
Unified_communications_manager Cisco 7.0(1)su1 (including) 7.0(1)su1 (including)
Unified_communications_manager Cisco 7.0(1)su1a (including) 7.0(1)su1a (including)
Unified_communications_manager Cisco 7.0(2) (including) 7.0(2) (including)
Unified_communications_manager Cisco 7.0(2a) (including) 7.0(2a) (including)
Unified_communications_manager Cisco 7.0(2a)su1 (including) 7.0(2a)su1 (including)
Unified_communications_manager Cisco 7.0(2a)su2 (including) 7.0(2a)su2 (including)
Unified_communications_manager Cisco 7.1(2a) (including) 7.1(2a) (including)
Unified_communications_manager Cisco 7.1(2a)su1 (including) 7.1(2a)su1 (including)
Unified_communications_manager Cisco 7.1(2b) (including) 7.1(2b) (including)
Unified_communications_manager Cisco 7.1(2b)su1 (including) 7.1(2b)su1 (including)
Unified_communications_manager Cisco 7.1(3) (including) 7.1(3) (including)
Unified_communications_manager Cisco 7.1(3a) (including) 7.1(3a) (including)
Unified_communications_manager Cisco 7.1(3a)su1 (including) 7.1(3a)su1 (including)
Unified_communications_manager Cisco 7.1(3a)su1a (including) 7.1(3a)su1a (including)
Unified_communications_manager Cisco 7.1(3b) (including) 7.1(3b) (including)
Unified_communications_manager Cisco 7.1(3b)su1 (including) 7.1(3b)su1 (including)
Unified_communications_manager Cisco 7.1(3b)su2 (including) 7.1(3b)su2 (including)
Unified_communications_manager Cisco 7.1(5) (including) 7.1(5) (including)
Unified_communications_manager Cisco 7.1(5)su1 (including) 7.1(5)su1 (including)
Unified_communications_manager Cisco 7.1(5)su1a (including) 7.1(5)su1a (including)
Unified_communications_manager Cisco 7.1(5a) (including) 7.1(5a) (including)
Unified_communications_manager Cisco 7.1(5b) (including) 7.1(5b) (including)
Unified_communications_manager Cisco 7.1(5b)su1 (including) 7.1(5b)su1 (including)
Unified_communications_manager Cisco 7.1(5b)su1a (including) 7.1(5b)su1a (including)
Unified_communications_manager Cisco 7.1(5b)su2 (including) 7.1(5b)su2 (including)
Unified_communications_manager Cisco 7.1(5b)su3 (including) 7.1(5b)su3 (including)
Unified_communications_manager Cisco 7.1(5b)su4 (including) 7.1(5b)su4 (including)
Unified_communications_manager Cisco 7.1(5b)su5 (including) 7.1(5b)su5 (including)
Unified_communications_manager Cisco 7.1(5b)su6 (including) 7.1(5b)su6 (including)
Unified_communications_manager Cisco 8.0 (including) 8.0 (including)
Unified_communications_manager Cisco 8.0(1) (including) 8.0(1) (including)
Unified_communications_manager Cisco 8.0(2) (including) 8.0(2) (including)
Unified_communications_manager Cisco 8.0(2a) (including) 8.0(2a) (including)
Unified_communications_manager Cisco 8.0(2b) (including) 8.0(2b) (including)
Unified_communications_manager Cisco 8.0(2c) (including) 8.0(2c) (including)
Unified_communications_manager Cisco 8.0(2c)su1 (including) 8.0(2c)su1 (including)
Unified_communications_manager Cisco 8.0(3) (including) 8.0(3) (including)
Unified_communications_manager Cisco 8.0(3a) (including) 8.0(3a) (including)
Unified_communications_manager Cisco 8.0(3a)su1 (including) 8.0(3a)su1 (including)
Unified_communications_manager Cisco 8.0(3a)su2 (including) 8.0(3a)su2 (including)
Unified_communications_manager Cisco 8.0(3a)su3 (including) 8.0(3a)su3 (including)
Unified_communications_manager Cisco 8.5 (including) 8.5 (including)
Unified_communications_manager Cisco 8.5(1) (including) 8.5(1) (including)
Unified_communications_manager Cisco 8.5(1)su1 (including) 8.5(1)su1 (including)
Unified_communications_manager Cisco 8.5(1)su2 (including) 8.5(1)su2 (including)
Unified_communications_manager Cisco 8.5(1)su3 (including) 8.5(1)su3 (including)
Unified_communications_manager Cisco 8.5(1)su4 (including) 8.5(1)su4 (including)
Unified_communications_manager Cisco 8.5(1)su5 (including) 8.5(1)su5 (including)
Unified_communications_manager Cisco 8.6 (including) 8.6 (including)
Unified_communications_manager Cisco 8.6(1) (including) 8.6(1) (including)
Unified_communications_manager Cisco 8.6(1a) (including) 8.6(1a) (including)
Unified_communications_manager Cisco 8.6(2) (including) 8.6(2) (including)
Unified_communications_manager Cisco 8.6(2a) (including) 8.6(2a) (including)
Unified_communications_manager Cisco 8.6(2a)su1 (including) 8.6(2a)su1 (including)
Unified_communications_manager Cisco 8.6(2a)su2 (including) 8.6(2a)su2 (including)
Unified_communications_manager Cisco 8.6(2a)su3 (including) 8.6(2a)su3 (including)
Unified_communications_manager Cisco 8.6(3) (including) 8.6(3) (including)
Unified_communications_manager Cisco 8.6(4) (including) 8.6(4) (including)
Unified_communications_manager Cisco 9.0(1) (including) 9.0(1) (including)

References