CVE-2015-0597: Input Validation
Published Feb 2, 2015
·Updated
The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159.
Affected Software
1 affected component
Cisco Webex Meetings Server<=1.5\(.1.131\)
Event History
Feb 2, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0597?
CVE-2015-0597 has been assigned a medium severity rating due to its potential impact on administrative account security.
2
How do I fix CVE-2015-0597?
To fix CVE-2015-0597, upgrade to Cisco WebEx Meetings Server version 1.5.1.132 or later.
3
What systems are affected by CVE-2015-0597?
CVE-2015-0597 affects Cisco WebEx Meetings Server versions up to and including 1.5.1.131.
4
What is the impact of CVE-2015-0597?
The impact of CVE-2015-0597 allows remote attackers to enumerate administrative accounts through crafted packets.
5
Was CVE-2015-0597 fixed in the latest Cisco updates?
Yes, CVE-2015-0597 was addressed in later releases of Cisco WebEx Meetings Server.