CVE-2014-0722: Medium severity Cisco Unified Communications Manager vulnerability
Published Feb 13, 2014
·Updated
The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified use of this application, aka Bug ID CSCum05347.
Affected Software
1 affected component
Cisco Unified Communications Manager
Event History
Feb 13, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·05:24 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker can exploit the authentication-validation flaw in the log4jinit web application. No authentication is required.
2
What is the expected impact of successful exploitation?
Successful exploitation can cause denial of service in the form of performance degradation on Cisco Unified Communications Manager.