CVE-2015-4218: Infoleak
Published Jun 24, 2015
·Updated
The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.
Affected Software
10 affected components
Cisco Jabber Windows=9.6\(0\)
Cisco Jabber Windows=9.6\(1\)
Cisco Jabber Windows=9.6\(2\)
Cisco Jabber Windows=9.6\(3\)
Cisco Jabber Windows=9.7\(0\)
Cisco Jabber Windows=9.7\(1\)
Cisco Jabber Windows=9.7\(2\)
Cisco Jabber Windows=9.7\(3\)
Cisco Jabber Windows=9.7\(4\)
Cisco Jabber Windows=9.7\(5\)
Event History
Jun 24, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4218?
CVE-2015-4218 has a medium severity rating due to its potential for information disclosure.
2
How do I fix CVE-2015-4218?
To remediate CVE-2015-4218, upgrade to a non-vulnerable version of Cisco Jabber beyond 9.7(5).
3
What is the impact of CVE-2015-4218?
The impact of CVE-2015-4218 allows remote attackers to obtain sensitive information through manipulated GET requests.
4
What versions of Cisco Jabber are affected by CVE-2015-4218?
CVE-2015-4218 affects Cisco Jabber versions 9.6(0) to 9.7(5) on Windows.
5
Is CVE-2015-4218 a remote attack vector?
Yes, CVE-2015-4218 can be exploited by remote attackers.