First published: Thu Apr 19 2018(Updated: )
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker to view configuration parameters. Cisco Bug IDs: CSCvf20218.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =10.5\(2.10000.5\) | |
Cisco Unified Communications Manager | =11.0\(1.10000.10\) | |
Cisco Unified Communications Manager | =11.5\(1.10000.6\) | |
Cisco Unified Communications Manager | =12.0\(1.10000.10\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0266 is classified as a medium severity vulnerability.
You can mitigate CVE-2018-0266 by applying the latest patches and updates provided by Cisco for affected versions.
An authenticated remote attacker can exploit CVE-2018-0266 to view sensitive data.
CVE-2018-0266 affects Cisco Unified Communications Manager versions 10.5(2.10000.5), 11.0(1.10000.10), 11.5(1.10000.6), and 12.0(1.10000.10).
CVE-2018-0266 is caused by insufficient protection of database tables over the web interface.