VulnerabilityModified
CVE-2015-0763
Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session information via a crafted URL, aka Bug ID CSCuu60338.
MEDIUM 5.0EPSS 1.95%
Does this matter?
Lower severity and a low EPSS score (1.95%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session information via a crafted URL, aka Bug ID CSCuu60338.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cisco/unified meetingplace
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39162Vendor Advisory
- http://www.securitytracker.com/id/1032471Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39162Vendor Advisory
- http://www.securitytracker.com/id/1032471Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.