Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8 uses weak permissions for the D:\CommServer\Reports directory, which allows remote authenticated users to obtain sensitive information by reading files in this directory.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/32187 | third party advisory vendor advisory |
http://www.voipshield.com/research-details.php?id=130 | |
http://www.securityfocus.com/bid/31642 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45742 | vdb entry |
http://securitytracker.com/id?1021022 | vdb entry |
http://www.vupen.com/english/advisories/2008/2771 | vdb entry |
http://www.cisco.com/en/US/products/products_security_response09186a0080a0d861.html | vendor advisory |