The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on a CTC workstation, aka bug ID CSCea25049.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2006-04-07 03:04
Updated : 2018-10-30 09:26
NVD link : CVE-2006-1672
Mitre link : CVE-2006-1672
JSON object : View
CWE
Products Affected
cisco
- optical_networking_systems_software
- ons_15600
- transport_controller
- ons_15454_mspp
- ons_15310-cl_series