CVE-2015-6404: Infoleak
Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6404?
CVE-2015-6404 has a high severity rating due to its implications for sensitive credential exposure.
How do I fix CVE-2015-6404?
To address CVE-2015-6404, ensure you are running a version of Cisco Hosted Collaboration Mediation that has been patched to implement role-based access control.
Who is affected by CVE-2015-6404?
Users of Cisco Hosted Collaboration Solution version 10.6(3) Base are affected by CVE-2015-6404.
What are the risks associated with CVE-2015-6404?
The risks include unauthorized access to sensitive credential information through API exploitation.
Can CVE-2015-6404 be exploited remotely?
Yes, CVE-2015-6404 can be exploited remotely by authenticated users leveraging admin API access.