Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh84801.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/95605 | vdb entry |
http://tools.cisco.com/security/center/viewAlert.x?alertId=35479 | vendor advisory |
http://www.securityfocus.com/bid/69458 | vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3352 | vendor advisory |
http://secunia.com/advisories/60956 | third party advisory |
http://www.securitytracker.com/id/1030785 | vdb entry |