Описание
Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCur63497.
Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCur63497.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-8000
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98786
- http://secunia.com/advisories/62558
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8000
- http://tools.cisco.com/security/center/viewAlert.x?alertId=36467
- http://www.securityfocus.com/bid/71173
- http://www.securitytracker.com/id/1031240
EPSS
CVE ID
Связанные уязвимости
Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCur63497.
EPSS