This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Cisco First view 2014-05-25
Product Tidal Enterprise Scheduler Last view 2017-03-15
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:cisco:tidal_enterprise_scheduler:6.0.2:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:6.0.0:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:5.3.0:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:5.2.2:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:3.0.1:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:3.0.0:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:6.0.3:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:6.0.1:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:5.3.1:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:6.3.0.116:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:6.3.0:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:6.2.1.435:*:*:*:*:*:*:* 1
cpe:2.3:a:cisco:tidal_enterprise_scheduler:6.2.1.510:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
8.6 2017-03-15 CVE-2017-3846

A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote attacker to retrieve any file from the Client Manager Server. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted URL to the Client Manager Server. An exploit could allow the attacker to retrieve any file from the Cisco Workload Automation or Cisco Tidal Enterprise Scheduler Client Manager Server. This vulnerability affects the following products: Cisco Tidal Enterprise Scheduler Client Manager Server releases 6.2.1.435 and later, Cisco Workload Automation Client Manager Server releases 6.3.0.116 and later. Cisco Bug IDs: CSCvc90789.

6 2014-05-25 CVE-2014-3272

The Agent in Cisco Tidal Enterprise Scheduler (TES) 6.1 and earlier allows local users to gain privileges via crafted Tidal Job Buffers (TJB) parameters, aka Bug ID CSCuo33074.

CWE : Common Weakness Enumeration

%idName
100% (2) CWE-20 Improper Input Validation

Snort® IPS/IDS

Date Description
2017-03-16 Cisco CWA and TES Client Manager Server directory traversal attempt
RuleID : 42002 - Type : SERVER-WEBAPP - Revision : 1
2017-03-16 Cisco CWA and TES Client Manager Server directory traversal attempt
RuleID : 42001 - Type : SERVER-WEBAPP - Revision : 1