CVE-2015-0595
published 2015-02-02CVE-2015-0595: The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages from…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.85%
76.6th percentile
The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages from crafted GET requests, aka Bug ID CSCuj67079.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | <= 1.5\(.1.131\) | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8pq9-x4rm-g7vp: The XMLAPI in Cisco WebEx Meetings Server 1
ghsa_unreviewed·2022-05-17
CVE-2015-0595 [MEDIUM] CWE-200 GHSA-8pq9-x4rm-g7vp: The XMLAPI in Cisco WebEx Meetings Server 1
The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages from crafted GET requests, aka Bug ID CSCuj67079.
Cisco
Cisco WebEx Meetings Server XMLAPI Vulnerability
vendor_cisco·2015-01-30·CVSS 5.0
CVE-2015-0595 [MEDIUM] CWE-200 Cisco WebEx Meetings Server XMLAPI Vulnerability
Cisco WebEx Meetings Server XMLAPI Vulnerability
A vulnerability in the XML application programming interface (API) of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view sensitive information.
The vulnerability is due to improper sanitization of return messages. An attacker could exploit this vulnerability by sending crafted GET requests to a vulnerable device.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send crafted GET requests to the targeted device. This access requirement may reduce the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exis
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/62686http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0595http://tools.cisco.com/security/center/viewAlert.x?alertId=37238http://www.securityfocus.com/bid/72370http://www.securitytracker.com/id/1031676https://exchange.xforce.ibmcloud.com/vulnerabilities/100667http://secunia.com/advisories/62686http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0595http://tools.cisco.com/security/center/viewAlert.x?alertId=37238http://www.securityfocus.com/bid/72370http://www.securitytracker.com/id/1031676https://exchange.xforce.ibmcloud.com/vulnerabilities/100667
2015-02-02
Published