CVE-2019-12635: Cisco Content Security Management Appliance Information Disclosure Vulnerability
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12635?
CVE-2019-12635 is a vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software.
How does CVE-2019-12635 affect Cisco Content Security Management Appliance?
CVE-2019-12635 allows an authenticated, remote attacker to gain out-of-scope access to email on Cisco Content Security Management Appliance.
What is the severity of CVE-2019-12635?
The severity of CVE-2019-12635 is medium (4.3).
How can I fix CVE-2019-12635?
To fix CVE-2019-12635, apply the necessary updates and patches provided by Cisco.
Where can I find more information about CVE-2019-12635?
You can find more information about CVE-2019-12635 on the Cisco Security Advisory website.