The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=39494 | vendor advisory |
http://www.securitytracker.com/id/1032711 | vdb entry third party advisory |
http://www.securityfocus.com/bid/75377 | vdb entry third party advisory |