First published: Tue Jul 04 2017(Updated: )
A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack another user's session. More Information: CSCvc90346. Known Affected Releases: 12.1.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Collaboration Provisioning | =11.2_base | |
Cisco Prime Collaboration Provisioning | =11.5.0 | |
Cisco Prime Collaboration Provisioning | =11.6_base | |
Cisco Prime Collaboration Provisioning | =12.1_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6703 has been rated as a high severity vulnerability due to its potential for session hijacking.
To fix CVE-2017-6703, you should update Cisco Prime Collaboration Provisioning to a patched version that addresses the vulnerability.
CVE-2017-6703 affects Cisco Prime Collaboration Provisioning versions 11.2_base, 11.5.0, 11.6_base, and 12.1_base.
No, CVE-2017-6703 can be exploited by an unauthenticated remote attacker.
CVE-2017-6703 allows attackers to hijack another user's session, potentially leading to unauthorized access to sensitive information.