
CVE-2021-44228 – Apache Log4j2 Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-44228
10 Dec 2021 — Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.... • https://packetstorm.news/files/id/171626 • CWE-20: Improper Input Validation CWE-400: Uncontrolled Resource Consumption CWE-502: Deserialization of Untrusted Data CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') •

CVE-2021-1599 – Cisco Unified Customer Voice Portal Cross-Site Scripting Vulnerability
https://notcve.org/view.php?id=CVE-2021-1599
22 Jul 2021 — A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user. This vulnerability is due to insufficient input validation of a parameter that is used by the web-based management interface. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary code in the contex... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cvp-xss-yvE6L8Zq • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-16017 – Cisco Unified Customer Voice Portal Insecure Direct Object Reference Vulnerability
https://notcve.org/view.php?id=CVE-2019-16017
23 Sep 2020 — A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to execute Insecure Direct Object Reference actions on specific pages within the OAMP application. The vulnerability is due to insufficient input validation on specific pages of the OAMP application. An attacker could exploit this vulnerability by authenticating to Cisco Unified CVP and sending crafted HTTP reques... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200108-cvp-direct-obj-ref • CWE-20: Improper Input Validation CWE-264: Permissions, Privileges, and Access Controls •

CVE-2020-3402 – Cisco Unified Customer Voice Portal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-3402
02 Jul 2020 — A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because certain RMI listeners are not properly authenticated. An attacker could exploit this vulnerability by sending a crafted request to the affected listener. A successful exploit could allow the attacker to access sensitive information on an affected device. Una vul... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cvp-info-dislosure-NZBEwj9V • CWE-306: Missing Authentication for Critical Function •

CVE-2018-0139
https://notcve.org/view.php?id=CVE-2018-0139
22 Feb 2018 — A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of service (DoS) condition. The vulnerability is due to improper handling of a TCP connection request when the IVR connection is already established. An attacker could exploit this vulnerability by initiating a crafted connection to the IP address of the ta... • http://www.securityfocus.com/bid/103124 • CWE-20: Improper Input Validation •

CVE-2018-0086
https://notcve.org/view.php?id=CVE-2018-0086
18 Jan 2018 — A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to malformed SIP INVITE traffic received on the CVP during communications with the Cisco Virtualized Voice Browser (VVB). An attacker could exploit this vulnerability by sending malformed SIP INVITE traffic to the targeted appliance. An exploit could allow the attacker to impact... • http://www.securityfocus.com/bid/102745 • CWE-400: Uncontrolled Resource Consumption •

CVE-2017-12214
https://notcve.org/view.php?id=CVE-2017-12214
21 Sep 2017 — A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the OAMP and sending a crafted HTTP request. A successful exploit could allow the attacker to gain administrator privileges. The attacker must ... • http://www.securityfocus.com/bid/100931 • CWE-20: Improper Input Validation CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-0735
https://notcve.org/view.php?id=CVE-2015-0735
17 May 2015 — Cross-site request forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal (CVP) 10.5(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut93970. Vulnerabilidad de CSRF en Cisco Unified Customer Voice Portal (CVP) 10.5(1) permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios, también conocido como Bug ID CSCut93970. • http://tools.cisco.com/security/center/viewAlert.x?alertId=38868 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2013-1223
https://notcve.org/view.php?id=CVE-2013-1223
09 May 2013 — The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38372. El lector de log en Cisco Unified Customer Voice Portal (CVP) Software antes de v9.0.1 ES v11 no valida correctamente un parámetro sin especificar, lo que permite a atacantes remotos leer ficheros arbitrarios a través de peticiones modificadas (1) H... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp • CWE-20: Improper Input Validation •

CVE-2013-1220
https://notcve.org/view.php?id=CVE-2013-1220
09 May 2013 — The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148. El componente CallServer en Cisco Unified Customer Voice Portal (CVP) Software antes de v9.0.1 ES v11 permite a atacantes remotos causar una denegación de servicios (corte de llamada aceptada) a través de mensajes SIP INVITE malformados, también conocido como Bug ID CSCua65148. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp •