| Vulnerability Name: | CVE-2013-1168 (CCN-83357) | ||||||||
| Assigned: | 2013-04-10 | ||||||||
| Published: | 2013-04-10 | ||||||||
| Updated: | 2013-04-15 | ||||||||
| Summary: | The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 Patch 1 does not invalidate a session upon a logout action, which makes it easier for remote attackers to hijack sessions by leveraging knowledge of a session cookie, aka Bug ID CSCuc64885. | ||||||||
| CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-1168 Source: CCN Type: SA53014 Cisco Unified MeetingPlace Web Conferencing Server Arbitrary Login Vulnerability Source: CCN Type: cisco-sa-20130410-mp Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution Source: CISCO Type: Vendor Advisory 20130410 Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution Source: CCN Type: BID-59006 Cisco Unified MeetingPlace CVE-2013-1168 Authentication Bypass Vulnerability Source: XF Type: UNKNOWN cisco-cve20131168-sec-bypass(83357) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||