Cisco-SA-20130910-CVE-2013-5489
Cisco SocialMiner Sensitive Information GET Request Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
A vulnerability in some of the gadgets of Cisco SocialMiner could allow an unauthenticated, remote attacker to collect sensitive information. The vulnerability is due to sensitive information being transmitted within a gadget's GET request. An attacker could exploit this vulnerability by capturing the GET request of a SocialMiner gadget. An exploit could allow the attacker to collect sensitive information of the user authenticated to the affected system. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must be in the position to capture a GET request of a SocialMiner agent. Typically, these systems would reside on trusted, internal networks, in which an attacker would likely need access. This access requirement decreases the likelihood of a successful exploit.
| Product | CVE |
|---|---|
| Cisco SocialMiner | CVE-2013-5489 |