First published: Thu Feb 20 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make CAR modifications, aka Bug ID CSCum46468.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | <=10.0\(1\) | |
Cisco Unified Communications Manager | =3.3\(5\) | |
Cisco Unified Communications Manager | =3.3\(5\)sr1 | |
Cisco Unified Communications Manager | =3.3\(5\)sr2a | |
Cisco Unified Communications Manager | =4.1\(3\) | |
Cisco Unified Communications Manager | =4.1\(3\)sr1 | |
Cisco Unified Communications Manager | =4.1\(3\)sr2 | |
Cisco Unified Communications Manager | =4.1\(3\)sr3 | |
Cisco Unified Communications Manager | =4.1\(3\)sr4 | |
Cisco Unified Communications Manager | =4.2 | |
Cisco Unified Communications Manager | =4.2.1 | |
Cisco Unified Communications Manager | =4.2.2 | |
Cisco Unified Communications Manager | =4.2.3 | |
Cisco Unified Communications Manager | =4.2.3sr1 | |
Cisco Unified Communications Manager | =4.2.3sr2 | |
Cisco Unified Communications Manager | =4.2.3sr2b | |
Cisco Unified Communications Manager | =4.3 | |
Cisco Unified Communications Manager | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.