CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
Percentile
56.6%
A vulnerability in the administration.jsp page of Cisco SocialMiner could allow an unauthenticated, remote attacker to access sensitive information.
The vulnerability exists because the affected software implements an insecure HTTP connection between a Cisco SocialMiner client and server when handling the administration.jsp page. An attacker could exploit this vulnerability with commonly available tools by intercepting HTTP traffic between the Cisco SocialMiner client and server. A successful exploit could allow the attacker to access sensitive information related to the authenticated user of the affected software.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must be in the position to capture HTTP traffic between a SocialMiner client and server. Typically, these systems would reside on trusted, internal networks, in which an attacker would likely need access. This access requirement decreases the likelihood of a successful exploit.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | socialminer | any | cpe:2.3:a:cisco:socialminer:any:*:*:*:*:*:*:* |