Information Exposure Vulnerability in Atos Unify OpenScape UC Web Client
CVE-2019-19866
7.5HIGH
What is CVE-2019-19866?
The Atos Unify OpenScape UC Web Client prior to specified versions is susceptible to an information exposure vulnerability. Remote attackers can exploit this flaw by iterating through the conferenceId parameter in the JSON API. This enables them to enumerate scheduled conferences, revealing sensitive details such as conference numbers and access PINs, thereby potentially compromising the confidentiality of user data.