Boletines de Vulnerabilidades

Cisco Unified Communications Domain Manager URI Enumeration Vulnerability


Información sobre el sistema

   
Software afectado Cisco

Descripción

A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to map a file system structure.The vulnerability is due to different handling of existent and nonexistent paths. An attacker could exploit this vulnerability by enumerating all possible URIs and gathering the answers that the server gives to those paths. A successful exploit could allow the attacker to determine the file system structure and which URIs are valid resources.Cisco has

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151027-ucd?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Unified%20Communications%20Domain%20Manager%20URI%20Enumeration%20Vuln

Identificadores estándar

Propiedad Valor
CVE CVE-2015-6352.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-10-29

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT