
CVE-2014-3280
https://notcve.org/view.php?id=CVE-2014-3280
03 Jun 2014 — The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user information by visiting an unspecified Administration GUI web page, aka Bug IDs CSCun46045 and CSCun46116. El Framework web en VOSS en Cisco Unified Communications Domain Manager (CDM) 9.0(.1) y anteriores no implementa debidamente control de acceso, lo que permite a usuarios remotos autenti... • http://secunia.com/advisories/58400 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-3277
https://notcve.org/view.php?id=CVE-2014-3277
29 May 2014 — The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive user and group information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum77005. La interfaz gráfica de usuario (GUI) Administration en el Framework web en VOSS en Cisco Unified Communications Domain Manager (CDM) 9.0(.1) y anteriores no ... • http://secunia.com/advisories/58400 • CWE-287: Improper Authentication •

CVE-2014-3279
https://notcve.org/view.php?id=CVE-2014-3279
29 May 2014 — The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSCun39631 and CSCun39643. La interfaz gráfica de usuario (GUI) Administration en el Framewrok web en VOSS en Cisco Unified Communications Domain Manager (CDM) 9.0(.1) y anteriores no implementa debidamente control de acceso, lo que permite a atacantes re... • http://secunia.com/advisories/58400 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-3282
https://notcve.org/view.php?id=CVE-2014-3282
29 May 2014 — The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive number-translation information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum76930. La interfaz gráfica de usuario (GUI) Administration en el Framework web en VOSS en Cisco Unified Communications Domain Manager (CDM) 9.0(.1) y anteriores... • http://secunia.com/advisories/58400 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-3283
https://notcve.org/view.php?id=CVE-2014-3283
29 May 2014 — Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCun79731. Vulnerabilidad de redirección abierta en aplicaciones Self-Care Client Portal en el Framework web en VOSS en Cisco Unified Communications Domain Manager (CDM) 9.0(.1) y anteriores permite a atacantes remoto... • http://secunia.com/advisories/58400 • CWE-20: Improper Input Validation •