Information Exposure Vulnerability in Atos Unify OpenScape UC Web Client
CVE-2019-19866

7.5HIGH

Key Information:

Vendor

Atos

Vendor
CVE Published:
21 February 2020

What is CVE-2019-19866?

The Atos Unify OpenScape UC Web Client prior to specified versions is susceptible to an information exposure vulnerability. Remote attackers can exploit this flaw by iterating through the conferenceId parameter in the JSON API. This enables them to enumerate scheduled conferences, revealing sensitive details such as conference numbers and access PINs, thereby potentially compromising the confidentiality of user data.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.