ID

VAR-201305-0156


CVE

CVE-2013-1222


TITLE

Cisco Unified Customer Voice Portal of Tomcat Web Management Any custom in function Web Application launch vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2013-002613

DESCRIPTION

The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38379. Cisco Unified Customer Voice Portal is prone to a security-bypass vulnerability. Exploiting this issue could allow an attacker to bypass certain security restrictions and gain unauthorized access to the affected device. This issue is being tracked by Cisco Bug ID CSCub38379. Versions prior to Unified Customer Voice Portal (CVP) 9.0.1 ES 11 are vulnerable. The vulnerability is caused by the program not configuring the Tomcat component correctly

Trust: 1.98

sources: NVD: CVE-2013-1222 // JVNDB: JVNDB-2013-002613 // BID: 59740 // VULHUB: VHN-61224

AFFECTED PRODUCTS

vendor:ciscomodel:unified customer voice portalscope:eqversion:9.0

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:3.0

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:8.5\(1\)

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:8.0\(1\)

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:3.6\(10\)

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:7.0\(2\)

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:4.0\(2\)

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:7.0

Trust: 1.3

vendor:ciscomodel:unified customer voice portalscope:eqversion:4.1

Trust: 1.3

vendor:ciscomodel:unified customer voice portalscope:eqversion:4.0

Trust: 1.3

vendor:ciscomodel:unified customer voice portalscope:lteversion:9.0\(1\)

Trust: 1.0

vendor:ciscomodel:unified customer voice portalscope:ltversion:9.0.1 es 11

Trust: 0.8

vendor:ciscomodel:unified customer voice portalscope:eqversion:9.0\(1\)

Trust: 0.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:7.0(1)

Trust: 0.3

vendor:ciscomodel:unified customer voice portal 4.1 es11scope: - version: -

Trust: 0.3

vendor:ciscomodel:unified customer voice portal 4.0 es14scope: - version: -

Trust: 0.3

sources: BID: 59740 // JVNDB: JVNDB-2013-002613 // CNNVD: CNNVD-201305-187 // NVD: CVE-2013-1222

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-1222
value: HIGH

Trust: 1.0

NVD: CVE-2013-1222
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201305-187
value: HIGH

Trust: 0.6

VULHUB: VHN-61224
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-1222
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:C/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-61224
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:C/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-61224 // JVNDB: JVNDB-2013-002613 // CNNVD: CNNVD-201305-187 // NVD: CVE-2013-1222

PROBLEMTYPE DATA

problemtype:CWE-16

Trust: 1.9

sources: VULHUB: VHN-61224 // JVNDB: JVNDB-2013-002613 // NVD: CVE-2013-1222

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201305-187

TYPE

configuration error

Trust: 0.6

sources: CNNVD: CNNVD-201305-187

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-002613

PATCH

title:28982url:http://tools.cisco.com/security/center/viewAMBAlert.x?alertId=28982

Trust: 0.8

title:cisco-sa-20130508-cvpurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp

Trust: 0.8

title:29156url:http://tools.cisco.com/security/center/viewAlert.x?alertId=29156

Trust: 0.8

title:cisco-sa-20130508-cvpurl:http://www.cisco.com/cisco/web/support/JP/111/1117/1117965_cisco-sa-20130508-cvp-j.html

Trust: 0.8

sources: JVNDB: JVNDB-2013-002613

EXTERNAL IDS

db:NVDid:CVE-2013-1222

Trust: 2.8

db:BIDid:59740

Trust: 1.0

db:JVNDBid:JVNDB-2013-002613

Trust: 0.8

db:CNNVDid:CNNVD-201305-187

Trust: 0.7

db:SECUNIAid:53306

Trust: 0.6

db:CISCOid:20130508 MULTIPLE VULNERABILITIES IN CISCO UNIFIED CUSTOMER VOICE PORTAL SOFTWARE

Trust: 0.6

db:VULHUBid:VHN-61224

Trust: 0.1

sources: VULHUB: VHN-61224 // BID: 59740 // JVNDB: JVNDB-2013-002613 // CNNVD: CNNVD-201305-187 // NVD: CVE-2013-1222

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20130508-cvp

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-1222

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-1222

Trust: 0.8

url:http://secunia.com/advisories/53306

Trust: 0.6

url:http://www.securityfocus.com/bid/59740

Trust: 0.6

url:http://www.cisco.com/en/us/products/sw/custcosw/ps1006/index.html

Trust: 0.3

sources: VULHUB: VHN-61224 // BID: 59740 // JVNDB: JVNDB-2013-002613 // CNNVD: CNNVD-201305-187 // NVD: CVE-2013-1222

CREDITS

Alex Senkevitch

Trust: 0.9

sources: BID: 59740 // CNNVD: CNNVD-201305-187

SOURCES

db:VULHUBid:VHN-61224
db:BIDid:59740
db:JVNDBid:JVNDB-2013-002613
db:CNNVDid:CNNVD-201305-187
db:NVDid:CVE-2013-1222

LAST UPDATE DATE

2024-11-23T22:02:23.851000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-61224date:2013-05-09T00:00:00
db:BIDid:59740date:2013-05-08T00:00:00
db:JVNDBid:JVNDB-2013-002613date:2013-05-10T00:00:00
db:CNNVDid:CNNVD-201305-187date:2013-05-10T00:00:00
db:NVDid:CVE-2013-1222date:2024-11-21T01:49:08.597

SOURCES RELEASE DATE

db:VULHUBid:VHN-61224date:2013-05-09T00:00:00
db:BIDid:59740date:2013-05-08T00:00:00
db:JVNDBid:JVNDB-2013-002613date:2013-05-10T00:00:00
db:CNNVDid:CNNVD-201305-187date:2013-05-09T00:00:00
db:NVDid:CVE-2013-1222date:2013-05-09T12:31:19.190