A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-4226 A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correctly implement role permission controls. An attacker could exploit this vulnerability by using a custom role with specific permissions. A successful exploit could allow the attacker to access the spam quarantine of other users.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 21 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-21T19:14:44.315Z

Reserved: 2019-06-04T00:00:00

Link: CVE-2019-12635

cve-icon Vulnrichment

Updated: 2024-08-04T23:24:39.174Z

cve-icon NVD

Status : Modified

Published: 2019-09-05T02:15:12.683

Modified: 2024-11-21T04:23:14.110

Link: CVE-2019-12635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.