CVE-2018-0267: Infoleak
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker to view sensitive information that should have been restricted. Cisco Bug IDs: CSCvf22116.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0267?
CVE-2018-0267 is rated as a medium severity vulnerability.
How do I fix CVE-2018-0267?
To mitigate CVE-2018-0267, update to the latest version of Cisco Unified Communications Manager.
Who is affected by CVE-2018-0267?
CVE-2018-0267 affects users of Cisco Unified Communications Manager versions 10.5(2.10000.5), 11.0(1.10000.10), 11.5(1.10000.6), and 12.0(1.10000.10).
What type of data can be compromised due to CVE-2018-0267?
CVE-2018-0267 could allow attackers to view sensitive data, including LDAP credentials.
What causes CVE-2018-0267?
CVE-2018-0267 is caused by insufficient protection of database tables over the web interface of Cisco Unified Communications Manager.