CVE-2015-0763
published 2015-06-04CVE-2015-0763: Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session information…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.95%
77.9th percentile
Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session information via a crafted URL, aka Bug ID CSCuu60338.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| cisco | unified_meetingplace | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache6.3MEDIUM
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified MeetingPlace Session ID Information Disclosure Vulnerability
vendor_cisco·2015-06-02·CVSS 5.0
CVE-2015-0763 [MEDIUM] CWE-200 Cisco Unified MeetingPlace Session ID Information Disclosure Vulnerability
Cisco Unified MeetingPlace Session ID Information Disclosure Vulnerability
A vulnerability in the Cisco Unified MeetingPlace application could allow an unauthenticated, remote attacker to obtain sensitive information.
The Cisco Unified MeetingPlace application does not always properly validate the session ID in the HTTP URL. This could allow an attacker to obtain sensitive information about a session to use to compromise the application.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the link.
Cisco indicates through the CVSS score that functional exploit code exists; howev
Apache
Apache tomcat: CVE-2016-0763
vendor_apache·CVSS 6.3
CVE-2016-0763 [MEDIUM] Apache tomcat: CVE-2016-0763
Apache tomcat: CVE-2016-0763
This issue only affects users running untrusted web applications under a security manager. ResourceLinkFactory.setGlobalContext() is a public method and was accessible to web applications even when running under a security manager. This allowed a malicious web application to inject a malicious global context that could in turn be used to disrupt other web applications and/or read and write data owned by other web applications. This was fixed in revision 1725929 . This issue was identified by the Tomcat security team on 18 January 2016 and made public on 22 February 2016. Affects: 8.0.0.RC1 to 8.0.30 6 December 2015 Fixed in Apache Tomcat 8.0.30 Low: Directory disclosure
GHSA
GHSA-6pf5-7qg8-j93f: Cisco Unified MeetingPlace 8
ghsa_unreviewed·2022-05-17
CVE-2015-0763 [MEDIUM] CWE-200 GHSA-6pf5-7qg8-j93f: Cisco Unified MeetingPlace 8
Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session information via a crafted URL, aka Bug ID CSCuu60338.
No detection rules found.
No public exploits indexed.
2015-06-04
Published