First published: Mon Aug 12 2013(Updated: )
Absolute path traversal vulnerability in the web interface in Cisco Finesse allows remote attackers to read directory contents via a direct request to a directory URL, aka Bug ID CSCug16772.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Finesse |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3457 is considered a medium severity vulnerability due to its ability to allow directory traversal and exposure of sensitive information.
To fix CVE-2013-3457, ensure that you apply the latest patches provided by Cisco for the Finesse application.
CVE-2013-3457 affects Cisco Finesse versions that have the web interface exposed to remote attackers.
Yes, CVE-2013-3457 can be exploited remotely by attackers accessing the web interface directly.
CVE-2013-3457 is classified as an absolute path traversal vulnerability.