First published: Fri Sep 13 2013(Updated: )
The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID CSCuh74125.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco SocialMiner |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5489 has been rated as a medium severity vulnerability.
To fix CVE-2013-5489, ensure that your Cisco SocialMiner software is updated to the latest version provided by Cisco.
CVE-2013-5489 can allow remote attackers to access sensitive information such as web-server access logs and browser history.
CVE-2013-5489 affects users of Cisco SocialMiner due to improper restrictions in the gadget implementation.
Currently, there are no documented workarounds for CVE-2013-5489; updating the software is the recommended approach.