Vulnerabilities > Cisco > Application Networking Manager > 1.1

DATE CVE VULNERABILITY TITLE RISK
2009-02-26 CVE-2009-0618 Multiple vulnerability in Cisco Application Networking Manager 1.1/1.2
Unspecified vulnerability in the Java agent in Cisco Application Networking Manager (ANM) before 2.0 Update A allows remote attackers to gain privileges, and cause a denial of service (service outage) by stopping processes, or obtain sensitive information by reading configuration files.
network
low complexity
cisco
8.5
2009-02-26 CVE-2009-0617 Credentials Management vulnerability in Cisco Application Networking Manager 1.1
Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL root password, which makes it easier for remote attackers to execute arbitrary operating-system commands or change system files.
network
low complexity
cisco CWE-255
critical
10.0
2009-02-26 CVE-2009-0616 Credentials Management vulnerability in Cisco Application Networking Manager 1.1
Cisco Application Networking Manager (ANM) before 2.0 uses default usernames and passwords, which makes it easier for remote attackers to access the application, or cause a denial of service via configuration changes, related to "default user credentials during installation."
network
low complexity
cisco CWE-255
critical
10.0
2009-02-26 CVE-2009-0615 Path Traversal vulnerability in Cisco products
Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related to "invalid directory permissions."
network
low complexity
cisco CWE-22
critical
9.0