Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco WebEx Meeting Server Sensitive Information Disclosure Vulnerability

Cisco-SA-20140611-CVE-2014-3294 · Medium · Published · Updated

A vulnerability in Cisco WebEx Meeting Server could allow an authenticated, remote attacker to acquire sensitive information.   The vulnerability is due to inclusion of sensitive information in URLs. An attacker could exploit this vulnerability by viewing application URL requests that contain the sensitive information. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. To exploit this vulnerability, an attacker must authenticate to an affected device. This access requirement decreases the likelihood of a successful exploit.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Administrators are advised to allow only trusted users to have network access.

Administrators are advised to monitor affected systems.

CVEsCVE-2014-3294
Cisco Bug IDsCSCuj81691
CVSS ScoreBase 4.0
Base 4.0 AV:N/AC:L/Au:S/C:P/I:N/A:N/E:H/RL:U/RC:C
Product Names From Source
Cisco WebEx Meetings Server

Related Products

Product CVE Evidence
Cisco Webex Meetings CVE-2014-3294 Cisco OpenVuln
Cisco WebEx Meetings Server CVE-2014-3294 Cisco OpenVuln