CVE-2013-5534: Path Traversal
Published Oct 19, 2013
·Updated
Directory traversal vulnerability in the attachment service in the Voice Message Web Service (aka VMWS or Cisco Unity Web Service) in Cisco Unity Connection allows remote authenticated users to create files, and consequently execute arbitrary JSP code, via a crafted pathname for a file that is not a valid audio file, aka Bug ID CSCuj22948.
Affected Software
1 affected component
Cisco Unity Connection
Event History
Oct 19, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5534?
CVE-2013-5534 is rated as a high severity vulnerability.
2
How do I fix CVE-2013-5534?
To mitigate CVE-2013-5534, update Cisco Unity Connection to the latest version provided by Cisco.
3
Who is affected by CVE-2013-5534?
Remote authenticated users of Cisco Unity Connection are affected by CVE-2013-5534.
4
What type of vulnerability is CVE-2013-5534?
CVE-2013-5534 is a directory traversal vulnerability.
5
What can an attacker achieve with CVE-2013-5534?
An attacker can create files and execute arbitrary JSP code through this vulnerability.