PT-2015-6510 · Cisco · Cisco Unified Web/E-Mail Interaction Manager
Publicado
2015-08-19
·
Atualizado
2016-12-28
·
CVE-2015-4299
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Web and E-Mail Interaction Manager version 9.0(2)
Description
The issue is related to improper authorization, allowing remote authenticated users to remove default messaging-queue system folders.
Recommendations
For Cisco Unified Web and E-Mail Interaction Manager version 9.0(2), update to a version that properly performs authorization to prevent unauthorized removal of system folders.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Unified Web/E-Mail Interaction Manager