漏洞信息详情
Cisco Unified Communications Manager IM和Presence Service 信息泄露漏洞
漏洞简介
Cisco Unified Communications Manager(CUCM,Unified CM)是美国思科(Cisco)公司的一款统一通信系统中的呼叫处理组件。Cisco Unified Communications Manager IM and Presence Service是一个基于CUCM的即时消息(IM)和状态显示平台。
CUCM IM和Presence Service中存在安全漏洞,该漏洞源于程序缺少对在HTTP数据包报头中运行的输入执行检测。远程攻击者可通过向目标设备上发送特制的数据包利用该漏洞浏览被限制的网页。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-ucm
参考网址
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-ucm
受影响实体
- Cisco Unified_communications_manager_im_and_presence_service:10.5%282%29<!--2000-1-1-->
- Cisco Unified_communications_manager_im_and_presence_service:11.5%281%29<!--2000-1-1-->
- Cisco Unified_communications_manager_im_and_presence_service:11.0%281%29<!--2000-1-1-->
- Cisco Unified_communications_manager_im_and_presence_service:10.5%281%29<!--2000-1-1-->
补丁
- Cisco Unified Communications Manager IM和Presence Service 信息泄露漏洞的修复措施<!--2016-12-9-->
还没有评论,来说两句吧...