is a service delivery and management platform that provides automation and administrative functions over the Cisco Unified Communications Manager, Cisco Unity Connection, and Cisco Jabber applications, as well as the associated phones and soft clients.

Cisco Unified Communications Domain Manager (Cisco Unified CDM)CUCDM is part of Cisco Hosted Collaboration System (HCS). The Cisco Unified CDM solution includes an Application Software and a Platform Software.A vulnerability in the web framework of the Cisco Unified Communications Domain Manager Application Software could allow an authenticated, remote attacker to elevate privileges and gain administrative access to the affected system.The vulnerability is due to improper implementation of authentication and authorization controls of the Administration GUI. An attacker could exploit this vulnerability by submitting a crafted URL to change the administrative credentials of a user. The attacker needs to be authenticated to the system or convince a valid user of the Administration GUI to click a malicious link.This vulnerability is documented in Cisco bug ID CSCun49862 registered customers only) and has been assigned Common Vulnerabilities and Exposures (CVE) identifier CVE-2014-2197.A vulnerability in the implementation of the framework that allows access to support representatives of the Cisco Unified Communications Domain Manager Platform Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user.The vulnerability is due to the presence of a default SSH private key, which is stored in an insecure way on the system. An attacker could exploit this vulnerability by obtaining the SSH private key. For example, the attacker might reverse engineer the binary file of the operating system. This will allow the attacker to connect by using the support account to the system without requiring any form of authentication. An exploit could allow the attacker to gain access to the system with the privileges of the root user.This vulnerability is documented in Cisco bug ID CSCud41130 registered customers only) and has been assigned CVE ID CVE-2014-2198.Due to an error in the fix, all Cisco Unified CDM Platform Software releases are vulnerable regardless if a previous patch has been applied due to this security advisory. Customers running any Cisco Unified CDM Platform Software release should request the hotfix patch called "ssh_keys_cleanup" through the normal support channel. The hotfix addresses only the Cisco Unified Communications Domain Manager Default SSH Key Vulnerability.The error in the fix is documented in Cisco bug ID CSCuq99452 registered customers only).A vulnerability in the web framework of Cisco Unified Communications Domain Manager Application Software could allow an unauthenticated, remote attacker to access and modify BVSMWeb portal user information such as settings in the personal phone directory, speed dials, Single Number Reach, and call forward settings.The vulnerability is due to improper implementation of authentication and authorization controls when accessing some web pages of the BVSMWeb portal. An attacker could exploit this vulnerability by submitting a crafted URL to the affected system.This vulnerability is documented in Cisco bug ID CSCum77041 registered customers only) and has been assigned CVE ID CVE-2014-3300