PT-2013-2909 · Cisco · Cisco Cloud Portal
Published
2013-02-27
·
Updated
2013-02-27
·
CVE-2013-1139
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Cloud Portal versions 9.1 SP1 through 9.1 SP2
Cisco Cloud Portal versions 9.3 through 9.3.2
Description
The issue concerns the nsAPI interface, which fails to properly check privileges. This allows remote authenticated users to obtain sensitive information by using a crafted URL.
Recommendations
For Cisco Cloud Portal versions 9.1 SP1 and 9.1 SP2, update to a version that properly checks privileges for the nsAPI interface.
For Cisco Cloud Portal versions 9.3 through 9.3.2, update to a version that properly checks privileges for the nsAPI interface.
As a temporary workaround, consider restricting access to the nsAPI interface until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Cloud Portal