#VU46256 Information disclosure in Cisco Jabber - CVE-2020-3537
Published: September 3, 2020
Cisco Jabber
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper validation of message contents. A remote authenticated attacker can send specially crafted messages that contain Universal Naming Convention (UNC) links to a targeted user, convince the user to follow the provided link and gain unauthorized access to sensitive information on the system.