PT-2018-8827 · Cisco · Cisco Webex Teams
Published
2018-10-05
·
Updated
2024-05-23
·
CVE-2018-0436
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Webex Teams (affected versions not specified)
Description
A vulnerability could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The issue exists because the affected software performs insufficient checks for associations between user accounts and organization accounts. An attacker with administrator or compliance officer privileges for one organization account could exploit this by using those privileges to view and modify data for another organization account. No customer data was impacted by this issue.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Webex Teams