CVE-2014-0657

Cisco Unified Communications Manager < 9.1(1) - Authenticated Role-Based Access Control Bypass via Portal URL

Title source: llm
STIX 2.1

Description

The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly handle role restrictions, which allows remote authenticated users to bypass role-based access control via multiple visits to a forbidden portal URL, aka Bug ID CSCuj83540.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/101800
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90120
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56368
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64690
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029571

Scores

EPSS 0.0213
EPSS Percentile 80.1%

Details

CWE
CWE-264
Status published
Products (50)
cisco/unified_communications_manager 3.3\(5\)
cisco/unified_communications_manager 3.3\(5\)sr1
cisco/unified_communications_manager 3.3\(5\)sr2a
cisco/unified_communications_manager 4.1\(3\)
cisco/unified_communications_manager 4.1\(3\)sr1
cisco/unified_communications_manager 4.1\(3\)sr2
cisco/unified_communications_manager 4.1\(3\)sr3
cisco/unified_communications_manager 4.1\(3\)sr4
cisco/unified_communications_manager 4.2
cisco/unified_communications_manager 4.2.1
... and 40 more
Published Jan 08, 2014
Tracked Since Feb 18, 2026