Vulnerability Description
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on the platform, with their numbers and access PINs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atos | Unify Openscape Uc Web Client | 9.0 |
Related Weaknesses (CWE)
References
- https://networks.unify.com/security/advisories/OBSO-2002-01.pdfVendor Advisory
- https://unify.com/en/support/security-advisoriesVendor Advisory
- https://networks.unify.com/security/advisories/OBSO-2002-01.pdfVendor Advisory
- https://unify.com/en/support/security-advisoriesVendor Advisory
FAQ
What is CVE-2019-19866?
CVE-2019-19866 is a vulnerability with a CVSS score of 7.5 (HIGH). Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to get...
How severe is CVE-2019-19866?
CVE-2019-19866 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19866?
Check the references section above for vendor advisories and patch information. Affected products include: Atos Unify Openscape Uc Web Client.