CVE-2014-3301: Infoleak
Published Jul 26, 2014
·Updated
The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.
Affected Software
3 affected components
Cisco Webex Meetings Server<=1.5\(.1.131\)
Cisco Webex Meetings Server=1.5
Cisco Webex Meetings Server=1.5\(.1.6\)
Event History
Jul 26, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3301?
CVE-2014-3301 has a medium severity rating due to the risk of information disclosure.
2
How do I fix CVE-2014-3301?
To fix CVE-2014-3301, upgrade to a later version of Cisco WebEx Meetings Server that addresses this vulnerability.
3
What kind of information can be exposed due to CVE-2014-3301?
CVE-2014-3301 can expose sensitive information through stack traces in error messages.
4
Which versions of Cisco WebEx Meetings Server are affected by CVE-2014-3301?
Versions 1.5 and earlier of Cisco WebEx Meetings Server are affected by CVE-2014-3301.
5
Who are the potential attackers for CVE-2014-3301?
Remote attackers can exploit CVE-2014-3301 to access sensitive information.