peter bassill · operator
$ cve CVE-2013-5528 JSON

CVE-2013-5528 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 23.3% (pctl 98)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS23.31% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2013-10-11
Last modified2026-06-16

Affected (1)

VendorProduct
ciscounified communications manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD