First published: Thu Jun 04 2015(Updated: )
Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session information via a crafted URL, aka Bug ID CSCuu60338.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified MeetingPlace | =8.6\(1.2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0763 is classified as a medium severity vulnerability.
To fix CVE-2015-0763, upgrade Cisco Unified MeetingPlace to version 8.6(1.3) or later.
CVE-2015-0763 specifically affects Cisco Unified MeetingPlace version 8.6(1.2).
CVE-2015-0763 is a session ID validation vulnerability that may lead to session hijacking.
Yes, CVE-2015-0763 can be exploited remotely through crafted HTTP URLs.