CVE-2013-1168

Cisco Unified MeetingPlace Application Server <7.1MR1-8.5MR3 - Sess...

Title source: llm
STIX 2.1

Description

The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 Patch 1 does not invalidate a session upon a logout action, which makes it easier for remote attackers to hijack sessions by leveraging knowledge of a session cookie, aka Bug ID CSCuc64885.

References (1)

Core 1
Core References

Scores

EPSS 0.0162
EPSS Percentile 73.6%

Details

Status published
Products (10)
cisco/unified_meetingplace 7.0
cisco/unified_meetingplace 7.0.1
cisco/unified_meetingplace 7.0.2 (2 CPE variants)
cisco/unified_meetingplace 7.0.3 (2 CPE variants)
cisco/unified_meetingplace 7.1 (2 CPE variants)
cisco/unified_meetingplace 8.0 (2 CPE variants)
cisco/unified_meetingplace 8.5
cisco/unified_meetingplace 8.5.1
cisco/unified_meetingplace 8.5.2
cisco/unified_meetingplace 8.5.3
Published Apr 11, 2013
Tracked Since Feb 18, 2026