Information Disclosure in Cisco Intelligent Automation for Cloud
CVE-2014-3297

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
2 July 2014

Summary

The Cisco Intelligent Automation for Cloud in Cisco Cloud Portal is susceptible to an information disclosure vulnerability due to improper restrictions on MyServices action URLs. This flaw permits remote authenticated users to access sensitive information, potentially allowing them to view web-server access logs, Referer logs, or browser history. It is crucial for organizations using this software to implement the necessary updates and security measures to mitigate these risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.