Known vulnerabilities in Cisco Jabber for Android and iOS
Vendor:
Cisco Systems, Inc
Software:
Cisco Jabber for Android and iOS
Software CPE:
cpe:2.3:a:cisco_systems:cisco_jabber_for_android_and_ios:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.2
Breakdown by Severity Chart
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU67953 - Exposure of resource to wrong sphere CVE-2022-20917 |
CWE-668 | Low | 14.1.4 | 06.10.2022 |
SB2022100613 |
||
| #VU54207 - Resource Management Errors CVE-2021-1570 |
CWE-399 | Low | 14.0.1 | 17.06.2021 |
SB2021061718 |
||
| #VU54206 - Insufficiently Protected Credentials CVE-2021-1569 |
CWE-522 | Medium | 14.0.1 | 17.06.2021 |
SB2021061718 |
||
| #VU51727 - Improper Certificate Validation CVE-2021-1471 |
CWE-295 | Medium | - | 25.03.2021 |
SB2021032514 |
||
| #VU51724 - Improper input validation CVE-2021-1418 |
CWE-20 | Low | - | 25.03.2021 |
SB2021032514 |
||
| #VU48951 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2020-27134 |
CWE-89 | Medium | 12.9.4 | 14.12.2020 |
SB2020121403 |
||
| #VU48947 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-26085 |
CWE-79 | Low | 12.9.4 | 14.12.2020 |
SB2020121403 |