CVE-2016-1307

The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bug ID CSCuw79085.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:finesse:10.5\\\(1\\\)_base:*:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:11.0\\\(1\\\)_base:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:cisco:unified_contact_center_express:10.6\\\(1\\\):*:*:*:*:*:*:*

Information

Published : 2016-02-07 11:59

Updated : 2016-12-06 03:06


NVD link : CVE-2016-1307

Mitre link : CVE-2016-1307


JSON object : View

Products Affected

cisco

  • unified_contact_center_express
  • finesse
CWE
CWE-255

Credentials Management Errors

CWE-287

Improper Authentication