PT-2015-7205 · Cisco · Cisco Content Delivery System Manager

Publicado

2015-11-14

·

Atualizado

2016-12-07

·

CVE-2015-6364

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Content Delivery System Manager Software version 3.2
Description The issue allows remote attackers to obtain sensitive information via crafted URLs in REST API requests.
Recommendations For Cisco Content Delivery System Manager Software version 3.2, consider restricting access to the REST API until a patch is available. As a temporary workaround, avoid using crafted URLs in REST API requests to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6364

Produtos afetados

Cisco Content Delivery System Manager