
CVE-2021-44228 – Apache Log4j2 Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-44228
10 Dec 2021 — Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.... • https://packetstorm.news/files/id/171626 • CWE-20: Improper Input Validation CWE-400: Uncontrolled Resource Consumption CWE-502: Deserialization of Untrusted Data CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') •

CVE-2021-1599 – Cisco Unified Customer Voice Portal Cross-Site Scripting Vulnerability
https://notcve.org/view.php?id=CVE-2021-1599
22 Jul 2021 — A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user. This vulnerability is due to insufficient input validation of a parameter that is used by the web-based management interface. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary code in the contex... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cvp-xss-yvE6L8Zq • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-16017 – Cisco Unified Customer Voice Portal Insecure Direct Object Reference Vulnerability
https://notcve.org/view.php?id=CVE-2019-16017
23 Sep 2020 — A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to execute Insecure Direct Object Reference actions on specific pages within the OAMP application. The vulnerability is due to insufficient input validation on specific pages of the OAMP application. An attacker could exploit this vulnerability by authenticating to Cisco Unified CVP and sending crafted HTTP reques... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200108-cvp-direct-obj-ref • CWE-20: Improper Input Validation CWE-264: Permissions, Privileges, and Access Controls •

CVE-2020-3402 – Cisco Unified Customer Voice Portal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-3402
02 Jul 2020 — A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because certain RMI listeners are not properly authenticated. An attacker could exploit this vulnerability by sending a crafted request to the affected listener. A successful exploit could allow the attacker to access sensitive information on an affected device. Una vul... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cvp-info-dislosure-NZBEwj9V • CWE-306: Missing Authentication for Critical Function •

CVE-2018-0086
https://notcve.org/view.php?id=CVE-2018-0086
18 Jan 2018 — A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to malformed SIP INVITE traffic received on the CVP during communications with the Cisco Virtualized Voice Browser (VVB). An attacker could exploit this vulnerability by sending malformed SIP INVITE traffic to the targeted appliance. An exploit could allow the attacker to impact... • http://www.securityfocus.com/bid/102745 • CWE-400: Uncontrolled Resource Consumption •

CVE-2013-1223
https://notcve.org/view.php?id=CVE-2013-1223
09 May 2013 — The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38372. El lector de log en Cisco Unified Customer Voice Portal (CVP) Software antes de v9.0.1 ES v11 no valida correctamente un parámetro sin especificar, lo que permite a atacantes remotos leer ficheros arbitrarios a través de peticiones modificadas (1) H... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp • CWE-20: Improper Input Validation •

CVE-2013-1220
https://notcve.org/view.php?id=CVE-2013-1220
09 May 2013 — The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148. El componente CallServer en Cisco Unified Customer Voice Portal (CVP) Software antes de v9.0.1 ES v11 permite a atacantes remotos causar una denegación de servicios (corte de llamada aceptada) a través de mensajes SIP INVITE malformados, también conocido como Bug ID CSCua65148. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp •

CVE-2013-1224
https://notcve.org/view.php?id=CVE-2013-1224
09 May 2013 — Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to overwrite arbitrary files via a crafted (1) HTTP or (2) HTTPS request that triggers incorrect parameter validation, aka Bug ID CSCub38369. Vulnerabilidad de salto de directorio en el Resource Manager en Cisco Unified Customer Voice Protal (CVP) Software antes de v9.0.1 ES v11 que permite a atacantes remotos sobrescribir ficheros arbitrarios a través de... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2013-1225
https://notcve.org/view.php?id=CVE-2013-1225
09 May 2013 — Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366. Cisco Unified Customer Voice Portal (CVP) Software anterior a v9.0.1 ES v11 permite a atacantes remotos leer ficheros arbitrarios a través de peticiones Resource Manager (1) HTTP ó (2) HTT... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-1222
https://notcve.org/view.php?id=CVE-2013-1222
09 May 2013 — The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38379. La característica Tomcat Web Management en Cisco Unified Customer Voice Portal (CVP) Software antes de v9.0.1 ES v11 no configura correctamente los componentes Tomcat, lo que permite a atacantes remotos lanzar aplcia... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp • CWE-16: Configuration •