First published: Thu Oct 27 2011(Updated: )
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Contact Center Express | =7.0\(1\) | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(3e\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(3a\) | |
Cisco Unified Communications Manager Session Management Edition | =8.0\(2c\) | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(3c\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(2\) | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(2a\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(3b\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(2b\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =8.0\(2\) | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(1b\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(2b\) | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(1c\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(2\)su1a | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(2\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(3b\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(4\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =8.0\(2b\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(4\) | |
Cisco Unified Communications Manager Session Management Edition | =5.0 | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(2a\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(3b\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(3a\)su1a | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(5b\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(5\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(2b\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(4a\) | |
Cisco Unified Contact Center Express | =8.0\(1\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(3\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(3\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(4a\)su2 | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(2a\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(1\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(5b\) | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(3d\) | |
Cisco Unified Communications Manager Session Management Edition | =5.1.2 | |
Cisco Unified Communications Manager Session Management Edition | =7.0\(2a\) | |
Cisco Unified Communications Manager Session Management Edition | =8.0 | |
Cisco Unified Communications Manager Session Management Edition | =7.0\(1\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =7.0\(1\)su1a | |
Cisco Unified Contact Center Express | =7.0\(2\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(5\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(5a\) | |
Cisco Unified Contact Center Express | =6.0\(1\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(1b\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(3b\) | |
Cisco Unified Communications Manager Session Management Edition | =7.0\(2a\)su2 | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(3\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(5\) | |
Cisco Unified Contact Center Express | =8.5\(1\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(5b\)su1a | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(5\)su1a | |
Cisco Unified Communications Manager Session Management Edition | =8.0\(2a\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(5\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(1\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(3a\) | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(2\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =7.0\(2a\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =5.1\(3a\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(3a\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =6.0 | |
Cisco Unified Communications Manager Session Management Edition | =5.1 | |
Cisco Unified Communications Manager Session Management Edition | =8.0\(2c\)su1 | |
Cisco Unified Communications Manager Session Management Edition | =6.1\(1a\) | |
Cisco Unified Contact Center Express | =8.0\(2\) | |
Cisco Unified Communications Manager Session Management Edition | =7.0\(2\) | |
Cisco Unified Communications Manager Session Management Edition | =8.0\(1\) | |
Cisco Unified Communications Manager Session Management Edition | =7.1\(3b\)su2 | |
Cisco Unified IP Interactive Voice Response | ||
Cisco Unified IP Interactive Voice Response | =6.0\(1\) | |
Cisco Unified IP Interactive Voice Response | =7.0\(1\) | |
Cisco Unified IP Interactive Voice Response | =7.0\(2\) | |
Cisco Unified IP Interactive Voice Response | =8.0\(1\) | |
Cisco Unified IP Interactive Voice Response | =8.0\(2\) | |
Cisco Unified IP Interactive Voice Response | =8.5\(1\) | |
Cisco Unified Contact Center Express | =6.0\(1\) | |
Cisco Unified Contact Center Express | =7.0\(1\) | |
Cisco Unified Contact Center Express | =7.0\(2\) | |
Cisco Unified Contact Center Express | =8.0\(1\) | |
Cisco Unified Contact Center Express | =8.0\(2\) | |
Cisco Unified Contact Center Express | =8.5\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-3315 is considered critical due to its potential for unauthorized access and compromise of sensitive information.
To fix CVE-2011-3315, upgrade to Cisco Unified Communications Manager versions 6.1(5)SU2 or later, or apply appropriate patches provided by Cisco.
CVE-2011-3315 affects Cisco Unified Communications Manager versions 5.x through 8.x, as well as certain versions of Cisco Unified Contact Center Express and Cisco Unified IP IVR.
CVE-2011-3315 can enable directory traversal attacks, allowing an attacker to access restricted directories and files on vulnerable systems.
Currently, the suggested approach is to upgrade or patch affected systems, as no specific workaround has been recommended for CVE-2011-3315.