CVE-2014-8025: Infoleak
Published Dec 23, 2014
·Updated
The API in the Guest Server in Cisco Jabber, when HTML5 is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST response, aka Bug ID CSCus19801.
Affected Software
1 affected component
Cisco Jabber Guest
Event History
Dec 23, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8025?
CVE-2014-8025 is rated as a medium severity vulnerability.
2
How do I fix CVE-2014-8025?
To mitigate CVE-2014-8025, ensure that network communications are encrypted, ideally using HTTPS.
3
What type of attacks can CVE-2014-8025 lead to?
CVE-2014-8025 can lead to sensitive information disclosure through network sniffing.
4
Which products are affected by CVE-2014-8025?
CVE-2014-8025 affects the Cisco Jabber Guest API when HTML5 is used.
5
What information can be exposed due to CVE-2014-8025?
CVE-2014-8025 can expose sensitive information sent over HTTP GET or POST requests.