漏洞信息详情
Cisco Unified Communications Manager和Presence Server信息泄露漏洞
漏洞简介
Cisco Unified Communications Manager是企业级IP电话呼叫处理系统。
Cisco Unified Communications Manager 6.x,7.1(5b)su4之前的7.x版本,8.0,8.5(1)su2之前的8.5版本和Presence Server 6.x,7.x,8.0,8.5xnr之前的8.5版本中存在信息泄露漏洞。由于Cisco Unified Communications Manager和Cisco Unified Presence Server包含开发的查询接口,未经验证的远程攻击者可通过SSL会话连接此查询接口泄露下层数据库中的数据。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f532.shtml
参考网址
来源: BID
名称: 49299
链接:http://www.securityfocus.com/bid/49299
来源: CISCO
名称: 20110824 Open Query Interface in Cisco Unified Communications Manager and Cisco Unified Presence Server
链接:http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f532.shtml
来源:SECUNIA
名称:45772
链接:http://secunia.com/advisories/45772 来源:NSFOCUS 名称:17608 链接:http://www.nsfocus.net/vulndb/17608
受影响实体
- Cisco Unified_presence_server:8.5%283%29<!--2000-1-1-->
- Cisco Unified_presence_server:8.5%282%29<!--2000-1-1-->
- Cisco Unified_presence_server:8.5%281%29<!--2000-1-1-->
- Cisco Unified_presence_server:8.5<!--2000-1-1-->
- Cisco Unified_presence_server:8.0<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...