CVE-2013-1139

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
27/02/2013
Last modified:
11/04/2025

Description

The nsAPI interface in Cisco Cloud Portal 9.1 SP1 and SP2, and 9.3 through 9.3.2, does not properly check privileges, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCud81134.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:cloud_portal:9.1:sp1:*:*:*:*:*:*
cpe:2.3:a:cisco:cloud_portal:9.1:sp2:*:*:*:*:*:*
cpe:2.3:a:cisco:cloud_portal:9.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cloud_portal:9.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cloud_portal:9.3.2:*:*:*:*:*:*:*