Cisco SocialMiner administration.jsp HTTP Information Disclosure Vulnerability

Related Vulnerabilities: CVE-2013-5492  

A vulnerability in the administration.jsp page of Cisco SocialMiner could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability exists because the affected software implements an insecure HTTP connection between a Cisco SocialMiner client and server when handling the administration.jsp page. An attacker could exploit this vulnerability with commonly available tools by intercepting HTTP traffic between the Cisco SocialMiner client and server. A successful exploit could allow the attacker to access sensitive information related to the authenticated user of the affected software. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must be in the position to capture HTTP traffic between a SocialMiner client and server. Typically, these systems would reside on trusted, internal networks, in which an attacker would likely need access. This access requirement decreases the likelihood of a successful exploit.