CVE-2016-1373: SSRF
The gadgets-integration API in Cisco Finesse 8.5(1) through 8.5(5), 8.6(1), 9.0(1), 9.0(2), 9.1(1), 9.1(1)SU1, 9.1(1)SU1.1, 9.1(1)ES1 through 9.1(1)ES5, 10.0(1), 10.0(1)SU1, 10.0(1)SU1.1, 10.5(1), 10.5(1)ES1 through 10.5(1)ES4, 10.5(1)SU1, 10.5(1)SU1.1, 10.5(1)SU1.7, 10.6(1), 10.6(1)SU1, 10.6(1)SU2, and 11.0(1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted request, aka Bug ID CSCuw86623.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1373?
CVE-2016-1373 has been rated as a moderate severity vulnerability.
How do I fix CVE-2016-1373?
To remediate CVE-2016-1373, upgrade to a fixed version of Cisco Finesse as recommended in the Cisco Security Advisory.
What versions of Cisco Finesse are affected by CVE-2016-1373?
CVE-2016-1373 affects multiple versions of Cisco Finesse, including 8.5(1) through 8.5(5), 8.6(1), and 9.0(1) to 11.0(1).
What type of vulnerability is CVE-2016-1373?
CVE-2016-1373 is a vulnerability in the gadgets-integration API of Cisco Finesse.
Are there any known exploits for CVE-2016-1373?
As of the latest updates, there are no publicly available exploits specifically targeting CVE-2016-1373.