CVE-2016-1317: Infoleak
Published Feb 9, 2016
·Updated
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.
Affected Software
1 affected component
Zyxel GS1900-10HP firmware<2.50\(aazi.0\)c0
Event History
Feb 9, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1317?
CVE-2016-1317 has been classified as a medium severity vulnerability.
2
Who is affected by CVE-2016-1317?
CVE-2016-1317 affects Cisco Unified Communications Manager 11.5(0.98000.480) and potentially other versions.
3
How do I fix CVE-2016-1317?
To fix CVE-2016-1317, upgrade Cisco Unified Communications Manager to a version that addresses this vulnerability.
4
What does CVE-2016-1317 exploit?
CVE-2016-1317 allows remote authenticated users to access sensitive database table-name and entity-name information.
5
What is the potential impact of CVE-2016-1317?
The potential impact of CVE-2016-1317 includes unauthorized information disclosure to authenticated users.