First published: Sat Nov 16 2013(Updated: )
Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka Bug ID CSCui58222.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | <=9.1\(1\) | |
Cisco Unified Communications Manager | =3.3\(5\) | |
Cisco Unified Communications Manager | =3.3\(5\)sr1 | |
Cisco Unified Communications Manager | =3.3\(5\)sr2a | |
Cisco Unified Communications Manager | =4.1\(3\) | |
Cisco Unified Communications Manager | =4.1\(3\)sr1 | |
Cisco Unified Communications Manager | =4.1\(3\)sr2 | |
Cisco Unified Communications Manager | =4.1\(3\)sr3 | |
Cisco Unified Communications Manager | =4.1\(3\)sr4 | |
Cisco Unified Communications Manager | =4.2 | |
Cisco Unified Communications Manager | =4.2.1 | |
Cisco Unified Communications Manager | =4.2.2 | |
Cisco Unified Communications Manager | =4.2.3 | |
Cisco Unified Communications Manager | =4.2.3sr1 | |
Cisco Unified Communications Manager | =4.2.3sr2 | |
Cisco Unified Communications Manager | =4.2.3sr2b | |
Cisco Unified Communications Manager | =4.3 | |
Cisco Unified Communications Manager | =4.3\(1\) | |
Cisco Unified Communications Manager | =5.0 | |
Cisco Unified Communications Manager | =5.1 | |
Cisco Unified Communications Manager | =5.1\(1\) | |
Cisco Unified Communications Manager | =5.1\(1b\) | |
Cisco Unified Communications Manager | =5.1\(1c\) | |
Cisco Unified Communications Manager | =5.1\(2\) | |
Cisco Unified Communications Manager | =5.1\(2a\) | |
Cisco Unified Communications Manager | =5.1\(2b\) | |
Cisco Unified Communications Manager | =5.1\(3\) | |
Cisco Unified Communications Manager | =5.1\(3a\) | |
Cisco Unified Communications Manager | =5.1\(3c\) | |
Cisco Unified Communications Manager | =5.1\(3d\) | |
Cisco Unified Communications Manager | =5.1\(3e\) | |
Cisco Unified Communications Manager | =5.1.2 | |
Cisco Unified Communications Manager | =6.0 | |
Cisco Unified Communications Manager | =6.0\(1\) | |
Cisco Unified Communications Manager | =6.0\(1a\) | |
Cisco Unified Communications Manager | =6.0\(1b\) | |
Cisco Unified Communications Manager | =6.1\(1\) | |
Cisco Unified Communications Manager | =6.1\(1a\) | |
Cisco Unified Communications Manager | =6.1\(1b\) | |
Cisco Unified Communications Manager | =6.1\(2\) | |
Cisco Unified Communications Manager | =6.1\(2\)su1 | |
Cisco Unified Communications Manager | =6.1\(2\)su1a | |
Cisco Unified Communications Manager | =6.1\(3\) | |
Cisco Unified Communications Manager | =6.1\(3a\) | |
Cisco Unified Communications Manager | =6.1\(3b\) | |
Cisco Unified Communications Manager | =6.1\(3b\)su1 | |
Cisco Unified Communications Manager | =6.1\(4\) | |
Cisco Unified Communications Manager | =6.1\(4\)su1 | |
Cisco Unified Communications Manager | =6.1\(4a\) | |
Cisco Unified Communications Manager | =6.1\(4a\)su2 | |
Cisco Unified Communications Manager | =6.1\(5\) | |
Cisco Unified Communications Manager | =6.1\(5\)su1 | |
Cisco Unified Communications Manager | =6.1\(5\)su2 | |
Cisco Unified Communications Manager | =6.1\(5\)su3 | |
Cisco Unified Communications Manager | =7.0\(1\)su1 | |
Cisco Unified Communications Manager | =7.0\(1\)su1a | |
Cisco Unified Communications Manager | =7.0\(2\) | |
Cisco Unified Communications Manager | =7.0\(2a\) | |
Cisco Unified Communications Manager | =7.0\(2a\)su1 | |
Cisco Unified Communications Manager | =7.0\(2a\)su2 | |
Cisco Unified Communications Manager | =7.1\(2a\) | |
Cisco Unified Communications Manager | =7.1\(2a\)su1 | |
Cisco Unified Communications Manager | =7.1\(2b\) | |
Cisco Unified Communications Manager | =7.1\(2b\)su1 | |
Cisco Unified Communications Manager | =7.1\(3\) | |
Cisco Unified Communications Manager | =7.1\(3a\) | |
Cisco Unified Communications Manager | =7.1\(3a\)su1 | |
Cisco Unified Communications Manager | =7.1\(3a\)su1a | |
Cisco Unified Communications Manager | =7.1\(3b\) | |
Cisco Unified Communications Manager | =7.1\(3b\)su1 | |
Cisco Unified Communications Manager | =7.1\(3b\)su2 | |
Cisco Unified Communications Manager | =7.1\(5\) | |
Cisco Unified Communications Manager | =7.1\(5\)su1 | |
Cisco Unified Communications Manager | =7.1\(5\)su1a | |
Cisco Unified Communications Manager | =7.1\(5a\) | |
Cisco Unified Communications Manager | =7.1\(5b\) | |
Cisco Unified Communications Manager | =7.1\(5b\)su1 | |
Cisco Unified Communications Manager | =7.1\(5b\)su1a | |
Cisco Unified Communications Manager | =7.1\(5b\)su2 | |
Cisco Unified Communications Manager | =7.1\(5b\)su3 | |
Cisco Unified Communications Manager | =7.1\(5b\)su4 | |
Cisco Unified Communications Manager | =7.1\(5b\)su5 | |
Cisco Unified Communications Manager | =7.1\(5b\)su6 | |
Cisco Unified Communications Manager | =8.0 | |
Cisco Unified Communications Manager | =8.0\(1\) | |
Cisco Unified Communications Manager | =8.0\(2\) | |
Cisco Unified Communications Manager | =8.0\(2a\) | |
Cisco Unified Communications Manager | =8.0\(2b\) | |
Cisco Unified Communications Manager | =8.0\(2c\) | |
Cisco Unified Communications Manager | =8.0\(2c\)su1 | |
Cisco Unified Communications Manager | =8.0\(3\) | |
Cisco Unified Communications Manager | =8.0\(3a\) | |
Cisco Unified Communications Manager | =8.0\(3a\)su1 | |
Cisco Unified Communications Manager | =8.0\(3a\)su2 | |
Cisco Unified Communications Manager | =8.0\(3a\)su3 | |
Cisco Unified Communications Manager | =8.5 | |
Cisco Unified Communications Manager | =8.5\(1\) | |
Cisco Unified Communications Manager | =8.5\(1\)su1 | |
Cisco Unified Communications Manager | =8.5\(1\)su2 | |
Cisco Unified Communications Manager | =8.5\(1\)su3 | |
Cisco Unified Communications Manager | =8.5\(1\)su4 | |
Cisco Unified Communications Manager | =8.5\(1\)su5 | |
Cisco Unified Communications Manager | =8.6 | |
Cisco Unified Communications Manager | =8.6\(1\) | |
Cisco Unified Communications Manager | =8.6\(1a\) | |
Cisco Unified Communications Manager | =8.6\(2\) | |
Cisco Unified Communications Manager | =8.6\(2a\) | |
Cisco Unified Communications Manager | =8.6\(2a\)su1 | |
Cisco Unified Communications Manager | =8.6\(2a\)su2 | |
Cisco Unified Communications Manager | =8.6\(2a\)su3 | |
Cisco Unified Communications Manager | =8.6\(3\) | |
Cisco Unified Communications Manager | =8.6\(4\) | |
Cisco Unified Communications Manager | =9.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6688 is considered a high-severity vulnerability due to its potential for unauthorized file creation.
To fix CVE-2013-6688, upgrade to a patched version of Cisco Unified Communications Manager that addresses the vulnerability.
CVE-2013-6688 affects remote authenticated users of Cisco Unified Communications Manager 9.1(1) and earlier.
Systems running Cisco Unified Communications Manager versions 9.1(1) and earlier, including several earlier versions listed in the advisory, are vulnerable.
Yes, CVE-2013-6688 can be exploited by remote authenticated users to create arbitrary files on the server.