Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCur63497.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=36467 | vendor advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8000 | vendor advisory |
http://secunia.com/advisories/62558 | third party advisory |
http://www.securityfocus.com/bid/71173 | vdb entry |
http://www.securitytracker.com/id/1031240 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98786 | vdb entry |