CVE-2015-4322: Medium severity cisco content security management vulnerability
Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary user's Spam Quarantine folder by visiting a spam-notification URL, aka Bug ID CSCuv65894.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4322?
CVE-2015-4322 has a moderate severity rating, which indicates potential impact on confidentiality and data integrity.
How do I fix CVE-2015-4322?
To fix CVE-2015-4322, update the Cisco Content Security Management Appliance to a version that includes the security patches provided by Cisco.
Who is affected by CVE-2015-4322?
Organizations using Cisco Content Security Management Appliance versions 8.3.6-039, 9.1.0-31, and 9.1.0-103 are affected by CVE-2015-4322.
What are the consequences of CVE-2015-4322?
CVE-2015-4322 could allow authenticated remote users to gain unauthorized access to another user's Spam Quarantine.
Is CVE-2015-4322 publicly known?
Yes, CVE-2015-4322 is a publicly disclosed vulnerability known to impact Cisco products.