PT-2014-5211 · Cisco · Cisco Unified Communications Manager

Publicado

2014-07-14

·

Atualizado

2017-08-29

·

CVE-2014-3317

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager version 10.0(1)
Description A directory traversal issue in the Multiple Analyzer component of the Dialed Number Analyzer (DNA) allows remote authenticated users to delete arbitrary files by using a crafted URL.
Recommendations For Cisco Unified Communications Manager version 10.0(1), update to a version that fixes this issue to prevent remote authenticated users from deleting arbitrary files.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3317

Produtos afetados

Cisco Unified Communications Manager