Input Validation Vulnerability in Cisco Jabber for Windows Client
CVE-2017-12284

5.5MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
19 October 2017

Summary

A flaw in the web interface of Cisco Jabber for Windows Client can allow an authenticated local attacker to access sensitive user profile information. This vulnerability arises from inadequate input- and validation-checking mechanisms. By executing targeted commands post-authentication, an attacker may exploit this vulnerability to reveal profile details that should remain restricted, potentially leading to significant data breaches. Relevant Cisco Bug IDs include CSCve14401.

Affected Version(s)

Cisco Jabber for Windows Client Cisco Jabber for Windows Client

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.