Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1033286 | vdb entry third party advisory |
http://www.securityfocus.com/bid/76348 | vdb entry third party advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=40428 | vendor advisory |