PT-2015-3698 · Apache+1 · Apache Tomcat+1

Publicado

2015-03-06

·

Atualizado

2015-11-30

·

CVE-2014-2130

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco Secure Access Control Server (ACS) (affected versions not specified)
Description The issue allows remote authenticated users with administrative privileges to modify application and configuration files, which can lead to the execution of arbitrary code. This is due to an unintentional administration web interface based on Apache Tomcat.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2130

Produtos afetados

Apache Tomcat
Cisco Secure Access Control Server