Unrated severityNVD Advisory· Published Aug 19, 2015· Updated May 6, 2026
CVE-2015-4322
CVE-2015-4322
Description
Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary user's Spam Quarantine folder by visiting a spam-notification URL, aka Bug ID CSCuv65894.
Affected products
3cpe:2.3:a:cisco:content_security_management_appliance:8.3.6-039:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cisco:content_security_management_appliance:8.3.6-039:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:content_security_management_appliance:9.1.0-103:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:content_security_management_appliance:9.1.0-31:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.