CVE Vulnerabilities

CVE-2015-4322

Published: Aug 19, 2015 | Modified: Sep 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary users Spam Quarantine folder by visiting a spam-notification URL, aka Bug ID CSCuv65894.

Affected Software

Name Vendor Start Version End Version
Content_security_management_appliance Cisco 8.3.6-039 (including) 8.3.6-039 (including)
Content_security_management_appliance Cisco 9.1.0-31 (including) 9.1.0-31 (including)
Content_security_management_appliance Cisco 9.1.0-103 (including) 9.1.0-103 (including)

References