CVE-2016-1317
published 2016-02-09CVE-2016-1317: Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information…
PriorityP421medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.17%
64.1th percentile
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| zyxel | gs1900-10hp_firmware | < 2.50\(aazi.0\)c0 | 2.50\(aazi.0\)c0 |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wx6v-v48x-7c97: Cisco Unified Communications Manager 11
ghsa_unreviewed·2022-05-17
CVE-2016-1317 [MEDIUM] CWE-200 GHSA-wx6v-v48x-7c97: Cisco Unified Communications Manager 11
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.
Cisco
Cisco Unified Communications Manager Information Disclosure Vulnerability
vendor_cisco·2016-02-08·CVSS 4.0
CVE-2016-1317 [MEDIUM] CWE-200 Cisco Unified Communications Manager Information Disclosure Vulnerability
Cisco Unified Communications Manager Information Disclosure Vulnerability
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data.
The vulnerability is due to insufficient protection of database tables. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker to view entity and table names.
Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-201600208-ucm
Cisco
Cisco Unified Communications Manager Information Disclosure Vulnerability
vendor_cisco
CVE-2016-1317 Cisco Unified Communications Manager Information Disclosure Vulnerability
CVE-2016-1317: Cisco Unified Communications Manager Information Disclosure Vulnerability
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker to view entity and table names. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-200, CWE-200
Bug IDs: CSCuy11098, CSCvb17829
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-02-09
Published