CVE-2017-3797: Infoleak
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view the fully qualified domain name of the Cisco WebEx administration server. More Information: CSCvb60655. Known Affected Releases: 2.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco WebEx Meetings Serverto a version that resolves this vulnerability.Fixed in 2.7Patch CSCvb60655
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3797?
CVE-2017-3797 has a medium severity rating as it allows unauthenticated attackers to view sensitive information.
How do I fix CVE-2017-3797?
To fix CVE-2017-3797, upgrade to a non-affected version of Cisco WebEx Meetings Server beyond 2.7.
Which versions of Cisco WebEx Meetings Server are affected by CVE-2017-3797?
CVE-2017-3797 affects Cisco WebEx Meetings Server versions 2.7.1 and 2.7_base.
Is authentication required to exploit CVE-2017-3797?
No, CVE-2017-3797 can be exploited by an unauthenticated remote attacker.
What information can be leaked due to CVE-2017-3797?
CVE-2017-3797 allows an attacker to view the fully qualified domain name of the Cisco WebEx administration server.