Sensitive Information Exposure in Cisco SocialMiner
CVE-2013-5489

Currently unrated

Key Information:

Vendor

Cisco

Vendor
CVE Published:
13 September 2013

What is CVE-2013-5489?

The gadget implementation in Cisco SocialMiner fails to effectively restrict the content of GET requests, which can inadvertently expose sensitive user data. This vulnerability potentially allows unauthorized remote attackers to gain access to critical information by reading web-server access logs, web-server Referer logs, or even the browser history. Such information exposure could lead to further security risks if exploited.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2013-5489 : Sensitive Information Exposure in Cisco SocialMiner