First published: Sat Jun 21 2014(Updated: )
The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server | <=1.5\(.1.131\) | |
Cisco Webex Meetings Server | =1.5\(.1.6\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3296 is classified as a medium severity vulnerability.
To fix CVE-2014-3296, upgrade to Cisco WebEx Meeting Server version 1.5(1.132) or later.
CVE-2014-3296 allows remote authenticated users to access sensitive meeting information.
CVE-2014-3296 affects Cisco WebEx Meeting Server versions up to and including 1.5(1.131).
Remote authenticated users of Cisco WebEx Meeting Server may be impacted by CVE-2014-3296.