CVE-2014-2197: Critical severity cisco unified communications domain manager platform vulnerability
The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allows remote authenticated users to modify administrative credentials via a crafted URL, aka Bug ID CSCun49862.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2197?
CVE-2014-2197 is rated as a medium severity vulnerability.
How do I fix CVE-2014-2197?
To fix CVE-2014-2197, upgrade Cisco Unified Communications Domain Manager to version 8.1.4 or later.
Who is affected by CVE-2014-2197?
CVE-2014-2197 affects users of Cisco Unified Communications Domain Manager and the Unified CDM Application Software before version 8.1.4.
What type of vulnerability is CVE-2014-2197?
CVE-2014-2197 is an access control vulnerability in the Administration GUI of Cisco Unified Communications Domain Manager.
Can remote authenticated users exploit CVE-2014-2197?
Yes, remote authenticated users can exploit CVE-2014-2197 to modify administrative credentials through crafted URLs.