Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-1222

Опубликовано: 09 мая 2013
Источник: nvd
CVSS2: 7.8
EPSS Низкий

Описание

The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38379.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:unified_customer_voice_portal:*:*:*:*:*:*:*:*
Версия до 9.0\(1\) (включая)
cpe:2.3:a:cisco:unified_customer_voice_portal:3.0:sr1:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:3.0:sr2:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:3.6\(10\):es01:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:4.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:4.0\(2\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:4.0\(2\):sr1:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:4.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:7.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:7.0\(2\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:8.0\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:8.5\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_customer_voice_portal:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00309
Низкий

7.8 High

CVSS2

Дефекты

CWE-16

Связанные уязвимости

github
больше 3 лет назад

The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38379.

EPSS

Процентиль: 54%
0.00309
Низкий

7.8 High

CVSS2

Дефекты

CWE-16