CVE-2015-4304: Critical severity cisco prime collaboration assurance vulnerability
The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictions, and create administrative accounts or read data from arbitrary tenant domains, via a crafted URL, aka Bug IDs CSCus62671 and CSCus62652.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4304?
CVE-2015-4304 is considered to have a high severity due to its ability to allow remote authenticated users to bypass access restrictions.
How do I fix CVE-2015-4304?
To fix CVE-2015-4304, upgrade your Cisco Prime Collaboration Assurance to a version that is not affected, specifically 10.5.1 or later.
What versions of Cisco Prime Collaboration Assurance are affected by CVE-2015-4304?
CVE-2015-4304 affects Cisco Prime Collaboration Assurance versions 9.0.0, 9.5.0, 10.0.0, 10.5.0, 10.5.1, and 10.6.0.
What are the potential impacts of CVE-2015-4304?
The potential impacts of CVE-2015-4304 include unauthorized creation of administrative accounts and reading data from arbitrary tenant domains.
Are there any workarounds for CVE-2015-4304?
There are no known workarounds for CVE-2015-4304; the recommended measure is to upgrade to a patched version.