Vulnerability Description
Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive information by reading HTML source code, aka Bug ID CSCui36976.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cloud Portal | - |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/58985
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3298Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34833Vendor Advisory
- http://www.securityfocus.com/bid/68309
- http://www.securitytracker.com/id/1030511
- http://secunia.com/advisories/58985
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3298Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34833Vendor Advisory
- http://www.securityfocus.com/bid/68309
- http://www.securitytracker.com/id/1030511
FAQ
What is CVE-2014-3298?
CVE-2014-3298 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive information by reading HTML ...
How severe is CVE-2014-3298?
CVE-2014-3298 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3298?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Cloud Portal.