5
CVSSv2

CVE-2015-4218

Published: 24/06/2015 Updated: 28/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The web-based user interface in Cisco Jabber up to and including 9.6(3) and 9.7 up to and including 9.7(5) on Windows allows remote malicious users to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco jabber 9.7\\(4\\)

cisco jabber 9.7\\(5\\)

cisco jabber 9.6\\(0\\)

cisco jabber 9.6\\(1\\)

cisco jabber 9.6\\(2\\)

cisco jabber 9.6\\(3\\)

cisco jabber 9.7\\(0\\)

cisco jabber 9.7\\(2\\)

cisco jabber 9.7\\(1\\)

cisco jabber 9.7\\(3\\)

Vendor Advisories

A vulnerability in the web-based user interface of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to have read access to information stored in the affected system The vulnerability is due to insufficient validation of specific values passed via HTTP GET methods by the affected software An attacker could exploit this vul ...