Lucene search

K
cveCiscoCVE-2014-3297
HistoryJul 02, 2014 - 10:35 a.m.

CVE-2014-3297

2014-07-0210:35:25
CWE-264
cisco
web.nvd.nist.gov
32
cve-2014-3297
cisco
intelligent automation
cloud
cloud portal
security vulnerability

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.002

Percentile

56.7%

Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug IDs CSCui36937, CSCui37004, and CSCui36927.

Affected configurations

Nvd
Node
ciscocloud_portalMatch-
VendorProductVersionCPE
ciscocloud_portal-cpe:2.3:a:cisco:cloud_portal:-:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.002

Percentile

56.7%

Related for CVE-2014-3297