First published: Tue Jun 23 2015(Updated: )
Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive information by obtaining a list of all meetings and then sending a calendar request for each one, aka Bug ID CSCur23913.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx Meeting Center |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4209 has a moderate severity level due to its potential to expose sensitive information.
To fix CVE-2015-4209, ensure you have the latest security patches installed for Cisco WebEx Meeting Center.
CVE-2015-4209 is an authorization bypass vulnerability that affects the reading of host calendars.
CVE-2015-4209 affects the Cisco WebEx Meeting Center software.
Yes, CVE-2015-4209 can lead to data leaks by allowing attackers to access sensitive meeting information.