CVE-2015-0705
published 2015-04-22CVE-2015-0705: Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified MeetingPlace 8.6(1.9) allows remote…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.29%
67.0th percentile
Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts, aka Bug ID CSCus97494.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_meetingplace | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified MeetingPlace Web Services Directory SOAP API Endpoints Cross-Site Request Forgery Vulnerability
vendor_cisco·2015-04-21·CVSS 6.8
CVE-2015-0705 [MEDIUM] CWE-352 Cisco Unified MeetingPlace Web Services Directory SOAP API Endpoints Cross-Site Request Forgery Vulnerability
Cisco Unified MeetingPlace Web Services Directory SOAP API Endpoints Cross-Site Request Forgery Vulnerability
A vulnerability in the SOAP application programming interface (API) endpoints of the web services directory of Cisco Unified MeetingPlace could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack.
The vulnerability is due to insufficient CSRF protections in the API endpoints. An attacker could exploit this vulnerability by convincing the administrator of the Cisco Unified MeetingPlace instance to visit an attacker-controlled website that unknowingly allows the creation of a new administrative user. A successful exploit could allow the attacker to use the new administrative user account to conduct further attacks.
Cisco has confirmed th
GHSA
GHSA-wpjr-v5gv-9429: Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified MeetingPlace 8
ghsa_unreviewed·2022-05-17
CVE-2015-0705 [MEDIUM] CWE-352 GHSA-wpjr-v5gv-9429: Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified MeetingPlace 8
Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts, aka Bug ID CSCus97494.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/viewAlert.x?alertId=38461http://www.securityfocus.com/bid/74258http://www.securitytracker.com/id/1032335https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667http://tools.cisco.com/security/center/viewAlert.x?alertId=38461http://www.securityfocus.com/bid/74258http://www.securitytracker.com/id/1032335https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667
2015-04-22
Published