Guest

Preview Tool

Cisco Bug: CSCul83786 - IMS not validating OAuth Tokens after 30 mins of recipt of first token

Last Modified

Aug 06, 2018

Products (1)

  • Cisco Unified Communications Manager (CallManager)

Known Affected Releases

10.5(0.98000.88)

Description (partial)

Symptoms:

A vulnerability in the Identity Management subsystem used by the WebApplications of Cisco Unified Communications Manager (CUCM) software could
allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

The vulnerability is due to invalid session requests.  An attacker could exploit this vulnerability by sending invalid session tokens to the
subsystem of an affected system. A successful exploit could allow the attacker to cause a denial of service condition to a specific application.
 A restart to the affected subsystem would be needed.


Conditions:
Only invalid oAuthToken Applications are affected.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.