CVE-2014-2130

Cisco Secure Access Control Server - Authenticated Arbitrary Code Execution via Apache Tomcat Administration Interface

Title source: llm
STIX 2.1

Description

Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka Bug ID CSCuj83189.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031844

Scores

EPSS 0.0403
EPSS Percentile 89.5%

Details

CWE
CWE-264
Status published
Products (1)
cisco/secure_access_control_system
Published Mar 06, 2015
Tracked Since Feb 18, 2026