Guest

Preview Tool

Cisco Bug: CSCur58721 - CUCDM Should Not Cache SessionID's via Browser

Last Modified

Aug 06, 2018

Products (1)

  • Cisco Hosted Collaboration Solution (HCS)

Known Affected Releases

10.1(2) 10.6(3)

Description (partial)

Symptom:
A vulnerability in Cisco Unified Communications Domain Manager (CUCDM) could allow an unauthenticated, remote attacker to conduct a Session
Hijacking attack.

The vulnerability is due to the session token being stolen or intercepted allowing unauthorized access to the Web Server. An attacker could
exploit this vulnerability by packet sniffing the session or performing client-side attacks such as Cross-Site Scripting (XSS) or a
man-in-the-middle attack.

Conditions:
Devices running an affected version of the Cisco Unified Communications Domain Manager.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.