Description
The nsAPI interface in Cisco Cloud Portal 9.1 SP1 and SP2, and 9.3 through 9.3.2, does not properly check privileges, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCud81134.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1139
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=28387
Scores
EPSS
0.0094
EPSS Percentile
57.1%
Details
CWE
CWE-264
Status
published
Products (4)
cisco/cloud_portal
9.1 sp1 (2 CPE variants)
cisco/cloud_portal
9.3
cisco/cloud_portal
9.3.1
cisco/cloud_portal
9.3.2
Published
Feb 27, 2013
Tracked Since
Feb 18, 2026