Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka Bug ID CSCuj83189.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2130 | Vendor Advisory |
http://www.securitytracker.com/id/1031844 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2015-03-06T02:00:00
Updated: 2015-03-16T16:57:00
Reserved: 2014-02-25T00:00:00
Link: CVE-2014-2130
JSON object: View
NVD Information
Status : Analyzed
Published: 2015-03-06T02:59:00.080
Modified: 2015-11-30T19:03:27.063
Link: CVE-2014-2130
JSON object: View
Redhat Information
No data.
CWE