#VU12061 Information disclosure in Unified Communications Manager (CallManager) - CVE-2018-0267
Published: April 18, 2018 / Updated: April 20, 2018
Unified Communications Manager (CallManager)
Cisco Systems, Inc
Description
The vulnerability allows a local authenticated attacker to obtain potentially sensitive information.
The weakness exists due to insufficient protection of database tables over the web interface. A local attacker can browse to a specific URL and gain access to potentially sensitive information including LDAP credentials.