Cisco Bug: CSCur58721 - CUCDM Should Not Cache SessionID's via Browser
Aug 06, 2018
- Cisco Hosted Collaboration Solution (HCS)
Known Affected Releases
Symptom: A vulnerability in Cisco Unified Communications Domain Manager (CUCDM) could allow an unauthenticated, remote attacker to conduct a Session Hijacking attack. The vulnerability is due to the session token being stolen or intercepted allowing unauthorized access to the Web Server. An attacker could exploit this vulnerability by packet sniffing the session or performing client-side attacks such as Cross-Site Scripting (XSS) or a man-in-the-middle attack. Conditions: Devices running an affected version of the Cisco Unified Communications Domain Manager.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases