Patch Date
Dec. 21, 2016
Vendor
Cisco
Systems Affected
Cisco Jabber Guest Server
Summary
A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts.
Vendor Status
We worked with Cisco to patch the affected application. A further write-up can be found here.
References
- CVE-2016-9224 : A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts.
- Cisco.com - Cisco Jabber Guest Server HTTP URL Redirection Vulnerability - 21Dec2016
Security Researcher
- Jake Miller of Bishop Fox