Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Prime_service_catalog | Cisco | 10.0(r2)_base (including) | 10.0(r2)_base (including) |
Prime_service_catalog | Cisco | 10.0_base (including) | 10.0_base (including) |
Prime_service_catalog | Cisco | 10.1_base (including) | 10.1_base (including) |
Prime_service_catalog | Cisco | 11.0_base (including) | 11.0_base (including) |