CVE-2015-4218
published 2015-06-24CVE-2015-4218: The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.63%
83.7th percentile
The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
| cisco | jabber | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Jabber for Windows Web-Based User Interface Information Disclosure Vulnerability
vendor_cisco·2015-06-23·CVSS 5.0
CVE-2015-4218 [MEDIUM] CWE-200 Cisco Jabber for Windows Web-Based User Interface Information Disclosure Vulnerability
Cisco Jabber for Windows Web-Based User Interface Information Disclosure Vulnerability
A vulnerability in the web-based user interface of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to have read access to information stored in the affected system.
The vulnerability is due to insufficient validation of specific values passed via HTTP GET methods by the affected software. An attacker could exploit this vulnerability by submitting crafted requests to a targeted system. If successful, the attacker could access sensitive system information from the system.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading lan
GHSA
GHSA-7c78-wvwc-9rw6: The web-based user interface in Cisco Jabber through 9
ghsa_unreviewed·2022-05-17
CVE-2015-4218 [MEDIUM] CWE-200 GHSA-7c78-wvwc-9rw6: The web-based user interface in Cisco Jabber through 9
The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-24
Published