CVE-2017-12286 (CNNVD-201710-882)
中文标题:
Cisco Jabber 信息泄露漏洞
英文标题:
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to...
漏洞描述
中文描述:
Cisco Jabber是美国思科(Cisco)公司的一套跨设备协作系统。该系统提供语音、视频、桌面共享和会议等功能。 Cisco Jabber中的Web界面存在信息泄露漏洞,该漏洞源于程序缺少输入和验证检测。本地攻击者可通过向受影响系统进行身份验证后,然后发送命令利用该漏洞检索用户配置文件信息。
英文描述:
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checks in the affected software. An attacker could exploit this vulnerability by authenticating locally to an affected system and then issuing specific commands to the affected software. A successful exploit could allow the attacker to view all profile information for a user instead of only certain Jabber parameters that should be visible. This vulnerability affects all releases of Cisco Jabber prior to Release 1.9.31. Cisco Bug IDs: CSCve52418.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | jabber | 1.9.30 | - | - |
cpe:2.3:a:cisco:jabber:1.9.30:*:*:*:*:windows:*:*
|
| cisco | webex_meeting_center | 1.9.26 | - | - |
cpe:2.3:a:cisco:webex_meeting_center:1.9.26:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-12286 |
2025-11-11 15:19:17 | 2025-11-11 07:34:33 |
| NVD | nvd_CVE-2017-12286 |
2025-11-11 14:55:32 | 2025-11-11 07:43:12 |
| CNNVD | cnnvd_CNNVD-201710-882 |
2025-11-11 15:09:54 | 2025-11-11 07:53:22 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-201710-882
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 5.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']