First published: Thu Jan 16 2014(Updated: )
The web portal in the Enterprise License Manager component in Cisco WebEx Meetings Server allows remote authenticated users to discover the cleartext administrative password by reading HTML source code, aka Bug ID CSCul33876.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6687 is classified as a medium-severity vulnerability due to its potential impact on administrative credentials.
To fix CVE-2013-6687, update to the latest version of Cisco Webex Meetings Server that addresses this issue.
Any organization using Cisco Webex Meetings Server is at risk of CVE-2013-6687 if they do not have the proper security measures in place.
CVE-2013-6687 represents an information disclosure vulnerability, allowing remote authenticated users to view administrative passwords.
There are no recommended workarounds for CVE-2013-6687; applying the available patch is the best course of action.