ID

VAR-201402-0217


CVE

CVE-2014-0735


TITLE

Cisco Unified Communications Manager of IP Manager Assistant Interface cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-001433

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum46470. Vendors have confirmed this vulnerability Bug ID CSCum46470 It is released as.Skillfully crafted by a third party URL Through any Web Script or HTML May be inserted. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCum46470. This component provides a scalable, distributed and highly available enterprise IP telephony call processing solution

Trust: 1.98

sources: NVD: CVE-2014-0735 // JVNDB: JVNDB-2014-001433 // BID: 65641 // VULHUB: VHN-68228

AFFECTED PRODUCTS

vendor:ciscomodel:unified communications managerscope:eqversion:4.3

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:4.2.3sr2b

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:4.2.1

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:4.1\(3\)sr4

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:4.2

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:4.2.3

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:4.2.3sr1

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:4.2.3sr2

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:4.1\(3\)sr3

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:4.2.2

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:3.3\(5\)

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:eqversion:3.3\(5\)sr2a

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:eqversion:3.3\(5\)sr1

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:lteversion:10.0\(1\)

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:eqversion:4.1\(3\)sr2

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:eqversion:4.1\(3\)

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:eqversion:10.0

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:eqversion:4.1\(3\)sr1

Trust: 1.0

vendor:ciscomodel:unified communications managerscope:lteversion:10.0(1)

Trust: 0.8

vendor:ciscomodel:unified communications managerscope:eqversion:0

Trust: 0.3

sources: BID: 65641 // JVNDB: JVNDB-2014-001433 // CNNVD: CNNVD-201402-275 // NVD: CVE-2014-0735

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-0735
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-0735
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201402-275
value: MEDIUM

Trust: 0.6

VULHUB: VHN-68228
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-0735
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-68228
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-68228 // JVNDB: JVNDB-2014-001433 // CNNVD: CNNVD-201402-275 // NVD: CVE-2014-0735

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-68228 // JVNDB: JVNDB-2014-001433 // NVD: CVE-2014-0735

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201402-275

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201402-275

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001433

PATCH

title:Cisco Unified Communications Manager IPMA Reflected Cross-Site Scripting Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0735

Trust: 0.8

title:32912url:http://tools.cisco.com/security/center/viewAlert.x?alertId=32912

Trust: 0.8

sources: JVNDB: JVNDB-2014-001433

EXTERNAL IDS

db:NVDid:CVE-2014-0735

Trust: 2.8

db:BIDid:65641

Trust: 1.4

db:SECTRACKid:1029793

Trust: 1.1

db:JVNDBid:JVNDB-2014-001433

Trust: 0.8

db:CNNVDid:CNNVD-201402-275

Trust: 0.7

db:SECUNIAid:56975

Trust: 0.6

db:CISCOid:20140218 CISCO UNIFIED COMMUNICATIONS MANAGER IPMA REFLECTED CROSS-SITE SCRIPTING VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-68228

Trust: 0.1

sources: VULHUB: VHN-68228 // BID: 65641 // JVNDB: JVNDB-2014-001433 // CNNVD: CNNVD-201402-275 // NVD: CVE-2014-0735

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-0735

Trust: 2.0

url:http://tools.cisco.com/security/center/viewalert.x?alertid=32912

Trust: 1.7

url:http://www.securityfocus.com/bid/65641

Trust: 1.1

url:http://www.securitytracker.com/id/1029793

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0735

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0735

Trust: 0.8

url:http://secunia.com/advisories/56975

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-68228 // BID: 65641 // JVNDB: JVNDB-2014-001433 // CNNVD: CNNVD-201402-275 // NVD: CVE-2014-0735

CREDITS

Cisco

Trust: 0.3

sources: BID: 65641

SOURCES

db:VULHUBid:VHN-68228
db:BIDid:65641
db:JVNDBid:JVNDB-2014-001433
db:CNNVDid:CNNVD-201402-275
db:NVDid:CVE-2014-0735

LAST UPDATE DATE

2024-11-23T22:39:03.469000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-68228date:2015-09-16T00:00:00
db:BIDid:65641date:2014-02-18T00:00:00
db:JVNDBid:JVNDB-2014-001433date:2014-02-21T00:00:00
db:CNNVDid:CNNVD-201402-275date:2014-02-21T00:00:00
db:NVDid:CVE-2014-0735date:2024-11-21T02:02:42.823

SOURCES RELEASE DATE

db:VULHUBid:VHN-68228date:2014-02-20T00:00:00
db:BIDid:65641date:2014-02-18T00:00:00
db:JVNDBid:JVNDB-2014-001433date:2014-02-21T00:00:00
db:CNNVDid:CNNVD-201402-275date:2014-02-21T00:00:00
db:NVDid:CVE-2014-0735date:2014-02-20T05:18:04.233