Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.
2015-12-12T11:59:00.120
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | prime_service_catalog | 10.0\(r2\)_base | Yes |
Application | cisco | prime_service_catalog | 10.0_base | Yes |
Application | cisco | prime_service_catalog | 10.1_base | Yes |
Application | cisco | prime_service_catalog | 11.0_base | Yes |