CVE-2015-4269
published 2015-07-14CVE-2015-4269: The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users to cause a denial of service…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.59%
73.1th percentile
The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users to cause a denial of service (management outage) by sending many requests, aka Bug ID CSCuu99709.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-53w7-2xj6-8f7m: The Tomcat throttling feature in Cisco Unified Communications Manager 10
ghsa_unreviewed·2022-05-17
CVE-2015-4269 [MEDIUM] GHSA-53w7-2xj6-8f7m: The Tomcat throttling feature in Cisco Unified Communications Manager 10
The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users to cause a denial of service (management outage) by sending many requests, aka Bug ID CSCuu99709.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerability
vendor_cisco·2015-07-13·CVSS 4.0
CVE-2015-4269 [MEDIUM] CWE-399 Cisco Unified Communications Manager Denial of Service Vulnerability
Cisco Unified Communications Manager Denial of Service Vulnerability
A vulnerability in the Tomcat service throttling mechanism of the Cisco Unified Communications Manager could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to sending multiple authenticated requests to Cisco Unified Communications Manager. An attacker could exploit this vulnerability by causing the Cisco Unified Communications Manager Management page to become slow or unresponsive.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement may reduce the likelihood of a successful exploit.
Cisco indicates through the CVSS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-14
Published