CVE-2017-3794: CSRF
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user. More Information: CSCuz03317. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco WebEx Meetings Serverto a version that resolves this vulnerability.Fixed in 2.7.1.12Patch CSCuz03317
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3794?
CVE-2017-3794 has been rated as a medium severity vulnerability.
How do I fix CVE-2017-3794?
To fix CVE-2017-3794, upgrade Cisco WebEx Meetings Server to version 2.7.1.12 or later.
What kind of attack can occur due to CVE-2017-3794?
CVE-2017-3794 allows an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack.
Which version of Cisco WebEx Meetings Server is affected by CVE-2017-3794?
Cisco WebEx Meetings Server version 2.6.0 is affected by CVE-2017-3794.
Is there a workaround for CVE-2017-3794?
There are no documented workarounds for CVE-2017-3794; upgrading to a fixed release is recommended.