CVE-2014-3296Sensitive Information Exposure in Cisco Webex Meetings Server

Severity
4.0MEDIUMNVD
EPSS
0.3%
top 48.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 21
Latest updateMay 17

Description

The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

NVDcisco/webex_meetings_server1.5\(.1.131\)+1

🔴Vulnerability Details

2
GHSA
GHSA-q98q-vph7-x77f: The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 12022-05-17
CVEList
CVE-2014-3296: The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 12014-06-21

📋Vendor Advisories

1
Cisco
Cisco WebEx Meeting Server Sensitive Information Disclosure Vulnerability2014-06-20
CVE-2014-3296 — Sensitive Information Exposure in Cisco | cvebase