"value":"A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system.\r\n\r This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"Server-Side Request Forgery (SSRF)",
"cweId":"CWE-918"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Cisco",
"product":{
"product_data":[
{
"product_name":"Cisco Unified Contact Center Enterprise",
"version":{
"version_data":[
{
"version_affected":"=",
"version_value":"N/A"
}
]
}
},
{
"product_name":"Cisco Unified Contact Center Express",
"version":{
"version_data":[
{
"version_affected":"=",
"version_value":"N/A"
}
]
}
},
{
"product_name":"Cisco Finesse",
"version":{
"version_data":[
{
"version_affected":"=",
"version_value":"12.6(2)"
},
{
"version_affected":"=",
"version_value":"12.6(2)ES1"
},
{
"version_affected":"=",
"version_value":"12.6(2)ES2"
}
]
}
},
{
"product_name":"Cisco Packaged Contact Center Enterprise",