First published: Thu Apr 19 2018(Updated: )
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker to view sensitive information that should have been restricted. Cisco Bug IDs: CSCvf22116.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =10.5\(2.10000.5\) | |
Cisco Unified Communications Manager | =11.0\(1.10000.10\) | |
Cisco Unified Communications Manager | =11.5\(1.10000.6\) | |
Cisco Unified Communications Manager | =12.0\(1.10000.10\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0267 is rated as a medium severity vulnerability.
To mitigate CVE-2018-0267, update to the latest version of Cisco Unified Communications Manager.
CVE-2018-0267 affects users of Cisco Unified Communications Manager versions 10.5(2.10000.5), 11.0(1.10000.10), 11.5(1.10000.6), and 12.0(1.10000.10).
CVE-2018-0267 could allow attackers to view sensitive data, including LDAP credentials.
CVE-2018-0267 is caused by insufficient protection of database tables over the web interface of Cisco Unified Communications Manager.