PT-2022-21802 · Unknown · Telephony-Common.Jar
Published
2022-07-11
·
Updated
2022-07-16
·
CVE-2022-33687
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
telephony-common.jar versions prior to SMR Jul-2022 Release 1
Description
The issue allows local attackers to access sensitive information, specifically the IMSI, via log exposure in the telephony-common.jar. This could potentially compromise user privacy.
Recommendations
For versions prior to SMR Jul-2022 Release 1, update to the SMR Jul-2022 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.
Fix
Information Disclosure
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Telephony-Common.Jar