Cisco SocialMiner Sensitive Information GET Request Vulnerability

Related Vulnerabilities: CVE-2013-5489  

A vulnerability in some of the gadgets of Cisco SocialMiner could allow an unauthenticated, remote attacker to collect sensitive information. The vulnerability is due to sensitive information being transmitted within a gadget's GET request. An attacker could exploit this vulnerability by capturing the GET request of a SocialMiner gadget. An exploit could allow the attacker to collect sensitive information of the user authenticated to the affected system. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must be in the position to capture a GET request of a SocialMiner agent. Typically, these systems would reside on trusted, internal networks, in which an attacker would likely need access. This access requirement decreases the likelihood of a successful exploit.