SB2018090612 - Security restrictions bypass in Cisco Webex Teams 



SB2018090612 - Security restrictions bypass in Cisco Webex Teams

Published: September 6, 2018

Security Bulletin ID SB2018090612
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2018-0436)

The vulnerability allows a remote authenticated attacker to bypass security restrictions.

The vulnerability exists due to the affected software performs insufficient checks for associations between user accounts and organization accounts. A remote attacker who has administrator or compliance officer privileges for one organization account can use those privileges to view and modify data for another organization account.


Remediation

Install update from vendor's website.