Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Unified_contact_center_enterprise
(Cisco)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 13 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-06-16 | CVE-2021-1395 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to... | Packaged_contact_center_enterprise, Unified_contact_center_enterprise, Unified_contact_center_express, Unified_intelligence_center | 6.1 | ||
2023-03-03 | CVE-2023-20061 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. | Packaged_contact_center_enterprise, Unified_contact_center_enterprise, Unified_contact_center_express, Unified_intelligence_center | 6.5 | ||
2023-03-03 | CVE-2023-20062 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. | Packaged_contact_center_enterprise, Unified_contact_center_enterprise, Unified_contact_center_express, Unified_intelligence_center | 4.3 | ||
2020-02-19 | CVE-2020-3163 | A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software improperly manages resources when processing inbound Live Data traffic. An attacker could exploit this vulnerability by sending multiple crafted Live Data packets to an affected device. A successful exploit could cause the affected device to... | Unified_contact_center_enterprise | N/A | ||
2017-05-03 | CVE-2017-6626 | A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allow an unauthenticated, remote attacker to retrieve information from agents using the Finesse Desktop. The vulnerability is due to the existence of a user account that has an undocumented, hard-coded password. An attacker could exploit this vulnerability by using the hard-coded credentials to subscribe to the Finesse Notification Service, which would allow... | Unified_contact_center_enterprise | 5.3 | ||
2016-06-22 | CVE-2016-1439 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux59650. | Unified_contact_center_enterprise | 6.1 | ||
2014-07-17 | CVE-2014-3323 | Directory traversal vulnerability in Cisco Unified Contact Center Enterprise allows remote authenticated users to read arbitrary web-root files via a crafted URL, aka Bug ID CSCun25262. | Unified_contact_center_enterprise | N/A | ||
2014-04-29 | CVE-2014-2180 | The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133. | Unified_contact_center_enterprise, Unified_contact_center_express_editor_software | N/A | ||
2007-10-17 | CVE-2007-5539 | Unspecified vulnerability in Cisco Unified Intelligent Contact Management Enterprise (ICME), Unified ICM Hosted (ICMH), Unified Contact Center Enterprise (UCCE), Unified Contact Center Hosted (UCCH), and System Unified Contact Center Enterprise (SUCCE) 7.1(5) allows remote authenticated users to gain privileges, and read reports or change the SUCCE configuration, via certain web interfaces, aka CSCsj55686. | Unified_contact_center_enterprise, Unified_contact_center_hosted, Unified_icm_hosted, Unified_intelligent_contact_management_enterprise | N/A | ||
2007-01-11 | CVE-2007-0198 | The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port. | Ip_contact_center_enterprise, Ip_contact_center_hosted, Unified_contact_center_enterprise, Unified_contact_center_hosted | N/A |