CVE-2013-1222

Published May 9, 2013

Last updated 3 months ago

Overview

Description
The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38379.
Source
ykramarz@cisco.com
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
7.8
Impact score
6.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:C/A:N

Weaknesses

nvd@nist.gov
CWE-16

Social media

Hype score
Not currently trending

Configurations