Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to the database-replication port, and consequently obtain sensitive information, via an SSL connection, aka Bug ID CSCue50794.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=30617 | vendor advisory |
http://www.securitytracker.com/id/1028972 | third party advisory vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3469 | vendor advisory |
http://www.securityfocus.com/bid/62091 | third party advisory vdb entry |