Vulnerabilities > Cisco > Unified Customer Voice Portal

DATE CVE VULNERABILITY TITLE RISK
2021-12-10 CVE-2021-44228 Deserialization of Untrusted Data vulnerability in multiple products
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints.
10.0
2021-07-22 CVE-2021-1599 Cross-site Scripting vulnerability in Cisco Unified Customer Voice Portal
A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user.
network
low complexity
cisco CWE-79
5.4
2020-07-02 CVE-2020-3402 Missing Authentication for Critical Function vulnerability in Cisco Unified Customer Voice Portal
A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device.
network
low complexity
cisco CWE-306
5.0
2018-02-22 CVE-2018-0139 Unspecified vulnerability in Cisco Unified Customer Voice Portal 11.5(1)/11.6
A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of service (DoS) condition.
network
low complexity
cisco
5.0
2018-01-18 CVE-2018-0086 Resource Exhaustion vulnerability in Cisco Unified Customer Voice Portal
A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device.
network
low complexity
cisco CWE-400
5.0
2017-09-21 CVE-2017-12214 Improper Input Validation vulnerability in Cisco Unified Customer Voice Portal 10.5/11.0/11.5
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges.
network
low complexity
cisco CWE-20
6.5
2015-05-17 CVE-2015-0735 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal 10.5(1)
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal (CVP) 10.5(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut93970.
network
cisco CWE-352
6.8
2014-07-19 CVE-2014-3325 Cross-Site Scripting vulnerability in Cisco Unified Customer Voice Portal
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Customer Voice Portal (CVP) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug IDs CSCuh61711, CSCuh61720, CSCuh61723, CSCuh61726, CSCuh61727, CSCuh61731, and CSCuh61733.
network
cisco CWE-79
4.3
2013-05-09 CVE-2013-1225 Permissions, Privileges, and Access Controls vulnerability in Cisco Unified Customer Voice Portal
Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366.
network
low complexity
cisco CWE-264
7.8
2013-05-09 CVE-2013-1224 Path Traversal vulnerability in Cisco Unified Customer Voice Portal
Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to overwrite arbitrary files via a crafted (1) HTTP or (2) HTTPS request that triggers incorrect parameter validation, aka Bug ID CSCub38369.
network
low complexity
cisco CWE-22
7.8