XML External Entity Injection in Cisco Unified Web and E-mail Interaction Manager
CVE-2014-2194
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 20 May 2014
Summary
The vulnerability in Cisco Unified Web and E-mail Interaction Manager allows remote attackers to exploit a flaw in the system's XML handling. By injecting a spoofed XML external entity, attackers can potentially manipulate data and execute unwanted commands, compromising the integrity and confidentiality of the application. This vulnerability highlights the importance of secure XML parsing practices to prevent malicious entity injection.
References
Timeline
Vulnerability published
Vulnerability Reserved