CVE-2014-3296: Infoleak
Published Jun 21, 2014
·Updated
The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.
Affected Software
2 affected components
Cisco Webex Meetings Server<=1.5\(.1.131\)
Cisco Webex Meetings Server=1.5\(.1.6\)
Event History
Jun 21, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3296?
CVE-2014-3296 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-3296?
To fix CVE-2014-3296, upgrade to Cisco WebEx Meeting Server version 1.5(1.132) or later.
3
What type of information is vulnerable in CVE-2014-3296?
CVE-2014-3296 allows remote authenticated users to access sensitive meeting information.
4
What are the affected versions in CVE-2014-3296?
CVE-2014-3296 affects Cisco WebEx Meeting Server versions up to and including 1.5(1.131).
5
Who is impacted by CVE-2014-3296?
Remote authenticated users of Cisco WebEx Meeting Server may be impacted by CVE-2014-3296.