Cisco Spark information leakage (CVE-2018-0119)
Cisco Spark information leakage (CVE-2018-0119)
Release date:
Updated on:
Affected Systems:
Cisco Spark
Description:
Bugtraq id: 102961
CVE (CAN) ID: CVE-2018-0119
Cisco Spark is a collaborative service.
Cisco Spark has security vulnerabilities in some authentication controls of the account service, allowing authenticated remote attackers to exploit this vulnerability to view information about the affected devices. This vulnerability is caused by incorrect display of user account tokens.
<* Source: Cisco
Link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-spark
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20180207-spark) and patches for this:
Cisco-sa-20180207-spark: Cisco Spark Information Disclosure Vulnerability
Link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-spark
This article permanently updates link: https://www.bkjia.com/Linux/2018-02/151078.htm