First published: Wed Jun 24 2015(Updated: )
Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading HTML source code, aka Bug ID CSCuu33050.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified MeetingPlace | =8.6\(1.2\) | |
Cisco Unified MeetingPlace | =8.6\(1.9\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4214 is considered a medium severity vulnerability due to the potential exposure of sensitive credentials.
To mitigate CVE-2015-4214, it is recommended to upgrade Cisco Unified MeetingPlace to a version that does not allow unauthorized password disclosure.
CVE-2015-4214 affects users of Cisco Unified MeetingPlace versions 8.6(1.2) and 8.6(1.9) when accessed by remote authenticated users.
CVE-2015-4214 is a security vulnerability that allows for the disclosure of cleartext passwords through the inspection of HTML source code.
No, CVE-2015-4214 requires remote authenticated access to exploit the vulnerability.