Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, aka Bug IDs CSCuh87398 and CSCuh87380.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/60960 | third party advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3351 | vendor advisory |
http://www.securityfocus.com/bid/69456 | vdb entry |
http://www.securitytracker.com/id/1030782 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95585 | vdb entry |