First published: Tue Mar 27 2018(Updated: )
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow the attacker to view data library information. Cisco Bug IDs: CSCvh66592.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0198 is considered a high severity vulnerability due to the potential for unauthenticated remote access to sensitive data.
To mitigate CVE-2018-0198, update your Cisco Unified Communications Manager to the latest version that addresses this vulnerability.
CVE-2018-0198 affects users of Cisco Unified Communications Manager, specifically those utilizing versions with the identified vulnerability.
An attacker can exploit CVE-2018-0198 by sending a request to a specific URL to access sensitive database information.
No, CVE-2018-0198 can be exploited by an unauthenticated attacker, making it particularly dangerous.