First published: Fri Nov 07 2014(Updated: )
The Unified Messaging Service (UMS) in Cisco Unity Connection 10.5 and earlier allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCur06493.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Connection 8.6 | <=10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7988 is classified as a medium severity vulnerability due to its potential to expose sensitive information to authenticated users.
To fix CVE-2014-7988, upgrade to Cisco Unity Connection 10.6 or later, which resolves the issue.
CVE-2014-7988 affects users of Cisco Unity Connection version 10.5 and earlier.
CVE-2014-7988 is an information disclosure vulnerability that allows remote authenticated users to access sensitive log files.
The consequences of CVE-2014-7988 include unauthorized access to sensitive log information, which may lead to further attacks or data breaches.