Description
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system.
Problem types
Product status
12.5(1)
12.5(1)SU1
12.5(1)SU2
12.5(1)SU3
12.5(1)SU4
14
12.5(1)SU5
14SU1
12.5(1)SU6
14SU2
12.5(1)SU7
14SU3
12.5(1)SU8
14SU3a
12.5(1)SU8a
15
15SU1
14SU4
12.5(1)SU9
15SU2
15SU3
14SU5
References
sec.cloudapps.cisco.com/...o-sa-unity-file-download-RmKEVWPx (cisco-sa-unity-file-download-RmKEVWPx)