First published: Sat Jul 26 2014(Updated: )
The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server | <=1.5\(.1.131\) | |
Cisco Webex Meetings Server | =1.5 | |
Cisco Webex Meetings Server | =1.5\(.1.6\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3301 has a medium severity rating due to the risk of information disclosure.
To fix CVE-2014-3301, upgrade to a later version of Cisco WebEx Meetings Server that addresses this vulnerability.
CVE-2014-3301 can expose sensitive information through stack traces in error messages.
Versions 1.5 and earlier of Cisco WebEx Meetings Server are affected by CVE-2014-3301.
Remote attackers can exploit CVE-2014-3301 to access sensitive information.