CVE-2017-12365: Infoleak
A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. The vulnerability is due to a design flaw in the product. An attacker could execute a query on an Event Center site to view scheduled meetings. A successful query would show both listed and unlisted meetings in the displayed information. An attacker could use this information to attend meetings that are not available for their attendance. Cisco Bug IDs: CSCvg33629.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco WebEx vulnerability?
The vulnerability ID is CVE-2017-12365.
What is the severity of CVE-2017-12365?
The severity of CVE-2017-12365 is medium with a CVSS score of 4.3.
How does CVE-2017-12365 affect Cisco WebEx Meeting Center?
CVE-2017-12365 allows an authenticated remote attacker to view unlisted meeting information in Cisco WebEx Meeting Center.
Is there a fix available for CVE-2017-12365?
Yes, Cisco has released a security advisory with fixes and mitigations for CVE-2017-12365.
Where can I find more information about CVE-2017-12365?
You can find more information about CVE-2017-12365 in the following references: [link](http://www.securityfocus.com/bid/101999), [link](http://www.securitytracker.com/id/1039920), [link](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-webex4).