Cisco Hosted Collaboration Solution vulnerabilities
9 known vulnerabilities affecting cisco/hosted_collaboration_solution.
Total CVEs
9
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2019-15968MEDIUMCVSS 5.4v8.1\(8\)er12019-11-26
CVE-2019-15968 [MEDIUM] CWE-79 CVE-2019-15968: A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager
A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied
nvd
CVE-2019-1911HIGHCVSS 7.8≤ 11.5\(3\)pb32019-07-06
CVE-2019-1911 [MEDIUM] CWE-216 CVE-2019-1911: A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Softwa
A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an authenticated, local attacker to escape the restricted shell. The vulnerability is due to insufficient input validation of shell commands. An attacker could exploit this vulnerability by executing crafted commands in the shell. A succe
nvd
CVE-2018-0386MEDIUMCVSS 6.1v11.5\(1\)2018-08-15
CVE-2018-0386 [MEDIUM] CWE-79 CVE-2018-0386: A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticat
A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulnerability is due to improper validation of input that is passed to the affected software. An attacker could exploit this vulnerability by persuading a user
nvd
CVE-2017-9805HIGHCVSS 8.1KEVPoCv10.5\(1\)v11.0\(1\)+2 more2017-09-15
CVE-2017-9805 [HIGH] CWE-502 CVE-2017-9805: The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an X
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
nvd
CVE-2015-6404MEDIUMCVSS 4.0v10.6\(3\)_base2015-12-15
CVE-2015-6404 [MEDIUM] CWE-200 CVE-2015-6404: Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote auth
Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374.
nvd
CVE-2015-6352MEDIUMCVSS 4.3v10.6_base2015-10-30
CVE-2015-6352 [MEDIUM] CWE-200 CVE-2015-6352: Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pat
Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID CSCut67891.
nvd
CVE-2015-4260MEDIUMCVSS 4.3v10.6\(1\)_base2015-07-10
CVE-2015-4260 [MEDIUM] CWE-79 CVE-2015-4260: Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remot
Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862.
nvd
CVE-2015-0750MEDIUMCVSS 6.5v8.0\(2\)_basev8.6\(1\)_base+10 more2015-05-23
CVE-2015-0750 [MEDIUM] CWE-264 CVE-2015-0750: The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier al
The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input to unspecified fields, aka Bug ID CSCut02786.
nvd
CVE-2015-0741MEDIUMCVSS 6.8≤ 10.6\(1\)2015-05-21
CVE-2015-0741 [MEDIUM] CWE-352 CVE-2015-0741: Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Prime Central for Hosted Collabo
Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(1) and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut04596.
nvd