CVE Vulnerabilities

CVE-2019-15963

Published: Sep 23, 2020 | Modified: Oct 29, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management interface of the affected software. The vulnerability is due to insufficient protection of user-supplied input by the web-based management interface of the affected service. An attacker could exploit this vulnerability by accessing the interface and viewing restricted portions of the software configuration. A successful exploit could allow the attacker to gain access to sensitive information or conduct further attacks.

Affected Software

Name Vendor Start Version End Version
Unified_communications_manager Cisco 10.5 (including) 10.5(2.10000.5) (including)
Unified_communications_manager Cisco 11.5 (including) 11.5(1.10000.6) (including)
Unified_communications_manager Cisco 12.0 (including) 12.0(1.10000.10) (including)
Unified_communications_manager Cisco 12.5 (including) 12.5(1.10000.22) (including)

References