First published: Mon Oct 13 2008(Updated: )
Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8 uses weak permissions for the D:\CommServer\Reports directory, which allows remote authenticated users to obtain sensitive information by reading files in this directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Server | <=4.2\(1\) | |
Cisco Unity Server | <=5.0\(1\) | |
Cisco Unity Server | <=7.0\(2\) | |
Cisco Unity Server | =4.0 | |
Cisco Unity Server | =4.0\(1\) | |
Cisco Unity Server | =4.0\(2\) | |
Cisco Unity Server | =4.0\(3\) | |
Cisco Unity Server | =4.0\(3\)-sr2 | |
Cisco Unity Server | =4.0\(4\) | |
Cisco Unity Server | =4.0\(4\)-sr1 | |
Cisco Unity Server | =4.0\(5\) | |
Cisco Unity Server | =4.1\(1\) | |
Cisco Unity Server | =5.0 | |
Cisco Unity Server | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4545 is classified as a moderate severity vulnerability.
To fix CVE-2008-4545, you need to update Cisco Unity to version 4.2(1)ES161, 5.0(1)ES53, or 7.0(2)ES8 or later.
CVE-2008-4545 affects Cisco Unity versions before 4.2(1)ES161, 5.0(1)ES53, and 7.0(2)ES8.
CVE-2008-4545 allows remote authenticated users to read sensitive files in the D:\CommServer\Reports directory.
Yes, Cisco has released updates that address the CVE-2008-4545 vulnerability.