The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attackers to obtain potentially sensitive user information by visiting an unspecified BVSMWeb web page, aka Bug IDs CSCun46071 and CSCun46101.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/58657 | third party advisory |
http://www.securityfocus.com/bid/67925 | vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3281 | vendor advisory |