CVE-2014-0723: XSS
Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum05343.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability can be exploited remotely without authentication by sending a crafted URL to the IP Manager Assistant interface. Exploitation requires user interaction with that URL, consistent with the medium access-complexity rating.
Which deployments are exposed?
Cisco Unified Communications Manager deployments are exposed where the IP Manager Assistant (IPMA) interface is accessible to an attacker. The available information does not identify affected versions or whether IPMA is enabled by default.
What is the likely impact of successful exploitation?
An attacker can inject arbitrary web script or HTML into the IPMA interface. The supplied severity vector indicates an integrity impact, with no listed confidentiality or availability impact.