SB2018090612 - Security restrictions bypass in Cisco Webex Teams
Published: September 6, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2018-0436)
The vulnerability allows a remote authenticated attacker to bypass security restrictions.
The vulnerability exists due to the affected software performs insufficient checks for associations between user accounts and organization accounts. A remote attacker who has administrator or compliance officer privileges for one organization account can use those privileges to view and modify data for another organization account.
Remediation
Install update from vendor's website.