CVE-2014-3294: Medium severity Cisco Webex Meetings Server vulnerability
Published Jun 10, 2014
·Updated
Cisco WebEx Meeting Server does not properly restrict the content of URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID CSCuj81691.
Affected Software
1 affected component
Cisco Webex Meetings Server
Event History
Jun 10, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·11:19 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker must be remotely authenticated to Cisco Webex Meetings Server. The issue does not require local access or user interaction.
2
Where could sensitive information be exposed?
Sensitive information may be obtainable from web-server access logs, web-server Referer logs, or browser history. Organizations should consider all three locations when assessing exposure.