7.5
CVE-2019-19866
- EPSS 0.53%
- Veröffentlicht 21.02.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on the platform, with their numbers and access PINs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atos ≫ Unify Openscape Uc Web Client Version9.0 Update-
Atos ≫ Unify Openscape Uc Web Client Version10.0 Update-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.662 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.